Unknown
CVE-2018-8013
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
Unknown
(0 users assessed)Unknown
(0 users assessed)Unknown
Unknown
Unknown
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
In Apache Batik 1.x before 1.10, when deserializing subclass of AbstractDocument
, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
- apache,
- canonical,
- debian,
- oracle
Products
- batik,
- business intelligence 11.1.1.7.0,
- business intelligence 11.1.1.9.0,
- business intelligence 12.2.1.3.0,
- business intelligence 12.2.1.4.0,
- communications diameter signaling router,
- communications metasolv solution 6.3.0,
- communications webrtc session controller,
- data integrator 12.2.1.3.0,
- debian linux 7.0,
- debian linux 8.0,
- debian linux 9.0,
- enterprise repository 11.1.1.7.0,
- enterprise repository 12.1.3.0.0,
- financial services analytical applications infrastructure,
- fusion middleware mapviewer 12.2.1.2,
- fusion middleware mapviewer 12.2.1.3,
- instantis enterprisetrack 17.1,
- instantis enterprisetrack 17.2,
- instantis enterprisetrack 17.3,
- insurance calculation engine 10.1.1,
- insurance calculation engine 10.2.1,
- insurance policy administration j2ee 10.0,
- insurance policy administration j2ee 10.2,
- jd edwards enterpriseone tools 9.2,
- retail back office 13.3,
- retail back office 13.4,
- retail back office 14,
- retail back office 14.1,
- retail central office 14.1,
- retail integration bus 17.0,
- retail order broker 15.0,
- retail order broker 16.0,
- retail order broker 5.1,
- retail order broker 5.2,
- retail point-of-service 13.4,
- retail point-of-service 14.0,
- retail point-of-service 14.1,
- retail returns management 14.1,
- ubuntu linux 14.04
References
Advisory
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: