Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
0

CVE-2018-8013

Disclosure Date: May 24, 2018
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
None
Impact Score:
Unknown
Exploitability Score:
Unknown
Vector:
Unknown
Attack Vector (AV):
Unknown
Attack Complexity (AC):
Unknown
Privileges Required (PR):
Unknown
User Interaction (UI):
Unknown
Scope (S):
Unknown
Confidentiality (C):
Unknown
Integrity (I):
Unknown
Availability (A):
Unknown

General Information

Vendors

  • apache,
  • canonical,
  • debian,
  • oracle

Products

  • batik,
  • business intelligence 11.1.1.7.0,
  • business intelligence 11.1.1.9.0,
  • business intelligence 12.2.1.3.0,
  • business intelligence 12.2.1.4.0,
  • communications diameter signaling router,
  • communications metasolv solution 6.3.0,
  • communications webrtc session controller,
  • data integrator 12.2.1.3.0,
  • debian linux 7.0,
  • debian linux 8.0,
  • debian linux 9.0,
  • enterprise repository 11.1.1.7.0,
  • enterprise repository 12.1.3.0.0,
  • financial services analytical applications infrastructure,
  • fusion middleware mapviewer 12.2.1.2,
  • fusion middleware mapviewer 12.2.1.3,
  • instantis enterprisetrack 17.1,
  • instantis enterprisetrack 17.2,
  • instantis enterprisetrack 17.3,
  • insurance calculation engine 10.1.1,
  • insurance calculation engine 10.2.1,
  • insurance policy administration j2ee 10.0,
  • insurance policy administration j2ee 10.2,
  • jd edwards enterpriseone tools 9.2,
  • retail back office 13.3,
  • retail back office 13.4,
  • retail back office 14,
  • retail back office 14.1,
  • retail central office 14.1,
  • retail integration bus 17.0,
  • retail order broker 15.0,
  • retail order broker 16.0,
  • retail order broker 5.1,
  • retail order broker 5.2,
  • retail point-of-service 13.4,
  • retail point-of-service 14.0,
  • retail point-of-service 14.1,
  • retail returns management 14.1,
  • ubuntu linux 14.04

References

Additional Info

Technical Analysis