Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Network
0

CVE-2020-11987

Disclosure Date: February 24, 2021
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
8.2 High
Impact Score:
4.2
Exploitability Score:
3.9
Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
Low
Availability (A):
None

General Information

Vendors

  • apache,
  • debian,
  • fedoraproject,
  • oracle

Products

  • agile engineering data management 6.2.1.0,
  • banking apis 18.3,
  • banking apis 19.1,
  • banking apis 19.2,
  • banking apis 20.1,
  • banking apis 21.1,
  • banking digital experience 18.3,
  • banking digital experience 19.1,
  • banking digital experience 19.2,
  • banking digital experience 20.1,
  • banking digital experience 21.1,
  • batik,
  • communications application session controller 3.9m0p3,
  • communications metasolv solution 6.3.0,
  • communications metasolv solution 6.3.1,
  • communications offline mediation controller 12.0.0.3.0,
  • debian linux 10.0,
  • enterprise repository 11.1.1.7.0,
  • fedora 33,
  • fedora 34,
  • flexcube universal banking,
  • fusion middleware mapviewer 12.2.1.4.0,
  • instantis enterprisetrack 17.1,
  • instantis enterprisetrack 17.2,
  • instantis enterprisetrack 17.3,
  • insurance policy administration,
  • product lifecycle analytics 3.6.1,
  • retail back office 14.1,
  • retail central office 14.1,
  • retail order broker 15.0,
  • retail order broker 16.0,
  • retail order management system cloud service 19.5,
  • retail point-of-service 14.1,
  • retail returns management 14.1,
  • weblogic server 12.2.1.3.0,
  • weblogic server 12.2.1.4.0,
  • weblogic server 14.1.1.0.0

Additional Info

Technical Analysis