Tracker / CVE-2020-11987
CVE-2020-11987
High 8.2
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected products and versions
| apache | batik · … → 1.13 |
|---|---|
| debian | debian_linux |
| fedoraproject | fedora |
| oracle | agile_engineering_data_management |
| oracle | banking_apis |
| oracle | banking_digital_experience |
| oracle | communications_application_session_controller |
| oracle | communications_metasolv_solution |
| oracle | communications_offline_mediation_controller |
| oracle | enterprise_repository |
| oracle | flexcube_universal_banking · 14.1.0 → 14.4.0 |
| oracle | fusion_middleware_mapviewer |
| oracle | instantis_enterprisetrack |
| oracle | insurance_policy_administration · 11.0 → 11.3.1 |
| oracle | product_lifecycle_analytics |
| oracle | retail_back_office |
| oracle | retail_central_office |
| oracle | retail_order_broker |
| oracle | retail_order_management_system_cloud_service |
| oracle | retail_point-of-service |
| oracle | retail_returns_management |
| oracle | weblogic_server |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.