Vulnerability Details CVE-2019-17566
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.1%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2019-17566
-
-
cpe:2.3:a:apache:batik:1.0
-
cpe:2.3:a:apache:batik:1.1
-
cpe:2.3:a:apache:batik:1.1.1
-
cpe:2.3:a:apache:batik:1.10
-
cpe:2.3:a:apache:batik:1.12
-
cpe:2.3:a:apache:batik:1.5
-
cpe:2.3:a:apache:batik:1.5.1
-
cpe:2.3:a:apache:batik:1.6
-
cpe:2.3:a:apache:batik:1.6.1
-
cpe:2.3:a:apache:batik:1.7
-
cpe:2.3:a:apache:batik:1.7.1
-
cpe:2.3:a:apache:batik:1.8
-
cpe:2.3:a:apache:batik:1.9
-
cpe:2.3:a:apache:batik:1.9.1
-
cpe:2.3:a:oracle:api_gateway:11.1.2.4.0
-
cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0
-
cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0
-
cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0
-
cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0
-
cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p2
-
cpe:2.3:a:oracle:communications_metasolv_solution:6.3.0
-
cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1
-
cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0
-
cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.0.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.0.1
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.1.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.2.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.3.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.6.4.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.0.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.1.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.7.2.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.8.0.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.9
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.0.9.0.0
-
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.0
-
cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.4.0
-
cpe:2.3:a:oracle:hospitality_opera_5:5.5
-
cpe:2.3:a:oracle:hospitality_opera_5:5.6
-
cpe:2.3:a:oracle:hyperion_financial_reporting:11.1.2.4
-
cpe:2.3:a:oracle:hyperion_financial_reporting:11.2.5.0
-
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1
-
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2
-
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:-
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:4.0.1.0
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.1
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.1.5
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.0.0
-
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.4.2
-
cpe:2.3:a:oracle:retail_integration_bus:15.0.3
-
cpe:2.3:a:oracle:retail_order_broker:15.0
-
cpe:2.3:a:oracle:retail_order_broker:16.0
-
cpe:2.3:a:oracle:retail_order_management_system_cloud_service:19.5
-
cpe:2.3:a:oracle:retail_point-of-service:14.1
-
cpe:2.3:a:oracle:retail_returns_management:14.1