CVE-2018-8013
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 19.29% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- apache/batik · debian/debian linux · canonical/ubuntu linux · oracle/business intelligence · oracle/communications diameter signaling router · oracle/communications metasolv solution · oracle/communications webrtc session controller · oracle/data integrator · oracle/enterprise repository · oracle/financial services analytical applications infrastructure · oracle/fusion middleware mapviewer · oracle/instantis enterprisetrack · oracle/insurance calculation engine · oracle/insurance policy administration j2ee · oracle/jd edwards enterpriseone tools · oracle/retail back office · oracle/retail central office · oracle/retail integration bus · oracle/retail order broker · oracle/retail point-of-service · +1 more
- Source
- security@apache.org
References
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/104252Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040995Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r9e90b4d1cf6ea87a79bb506541140dfbf4801f4463a7cee08126ee44%40%3Ccommits.xmlgraphics.apache.org%3E
- https://lists.apache.org/thread.html/rc0a31867796043fbe59113fb654fe8b13309fe04f8935acb8d0fab19%40%3Ccommits.xmlgraphics.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/05/msg00016.htmlMailing List, Third Party Advisory
- https://mail-archives.apache.org/mod_mbox/xmlgraphics-batik-dev/201805.mbox/%3c000701d3f28f%24d01860a0%24704921e0%24%40gmail.com%3e
- https://security.gentoo.org/glsa/202401-11
- https://usn.ubuntu.com/3661-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4215Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://xmlgraphics.apache.org/security.htmlThird Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/104252Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040995Third Party Advisory, VDB Entry
- https://lists.apache.org/thread.html/r9e90b4d1cf6ea87a79bb506541140dfbf4801f4463a7cee08126ee44%40%3Ccommits.xmlgraphics.apache.org%3E
- https://lists.apache.org/thread.html/rc0a31867796043fbe59113fb654fe8b13309fe04f8935acb8d0fab19%40%3Ccommits.xmlgraphics.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2018/05/msg00016.htmlMailing List, Third Party Advisory
- https://mail-archives.apache.org/mod_mbox/xmlgraphics-batik-dev/201805.mbox/%3c000701d3f28f%24d01860a0%24704921e0%24%40gmail.com%3e
- https://security.gentoo.org/glsa/202401-11
- https://usn.ubuntu.com/3661-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4215Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.