Tracker / CVE-2019-17566
CVE-2019-17566
Alta 7.5
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Prodotti e versioni affette
| apache | batik · … → 1.13 |
|---|---|
| oracle | api_gateway |
| oracle | business_intelligence |
| oracle | communications_application_session_controller |
| oracle | communications_metasolv_solution · 6.3.0 → 6.3.1 |
| oracle | communications_offline_mediation_controller |
| oracle | enterprise_repository |
| oracle | financial_services_analytical_applications_infrastructure · 8.0.6 → 8.1.0 |
| oracle | fusion_middleware_mapviewer |
| oracle | hospitality_opera_5 |
| oracle | hyperion_financial_reporting |
| oracle | instantis_enterprisetrack · 17.1 → 17.3 |
| oracle | jd_edwards_enterpriseone_tools |
| oracle | jd_edwards_enterpriseone_tools · … → 9.2.4.0 |
| oracle | retail_integration_bus |
| oracle | retail_order_broker |
| oracle | retail_order_management_system_cloud_service |
| oracle | retail_point-of-service |
| oracle | retail_returns_management |
Analisi
Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.