Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "10.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "debian:debian_linux"
},
{
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "33"
},
{
"last_affected": "34"
}
],
"source": "CPE_FIELD",
"vendor_product": "fedoraproject:fedora"
},
{
"cpes": [
"cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "6.2.1.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:agile_engineering_data_management"
},
{
"cpes": [
"cpe:2.3:a:oracle:banking_apis:18.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "18.3"
},
{
"last_affected": "19.1"
},
{
"last_affected": "19.2"
},
{
"last_affected": "20.1"
},
{
"last_affected": "21.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:banking_apis"
},
{
"cpes": [
"cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "18.3"
},
{
"last_affected": "19.1"
},
{
"last_affected": "19.2"
},
{
"last_affected": "20.1"
},
{
"last_affected": "21.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:banking_digital_experience"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "3.9m0p3"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_application_session_controller"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "6.3.0"
},
{
"last_affected": "6.3.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_metasolv_solution"
},
{
"cpes": [
"cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "12.0.0.3.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:communications_offline_mediation_controller"
},
{
"cpes": [
"cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "11.1.1.7.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:enterprise_repository"
},
{
"cpes": [
"cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "14.1.0"
},
{
"last_affected": "14.4.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:flexcube_universal_banking"
},
{
"cpes": [
"cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.4.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "12.2.1.4.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:fusion_middleware_mapviewer"
},
{
"cpes": [
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "17.1"
},
{
"last_affected": "17.2"
},
{
"last_affected": "17.3"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:instantis_enterprisetrack"
},
{
"cpes": [
"cpe:2.3:a:oracle:insurance_policy_administration:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "11.0"
},
{
"last_affected": "11.3.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:insurance_policy_administration"
},
{
"cpes": [
"cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "3.6.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:product_lifecycle_analytics"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_back_office"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_central_office"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "16.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_order_broker"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_order_management_system_cloud_service:19.5:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "19.5"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_order_management_system_cloud_service"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_point-of-service"
},
{
"cpes": [
"cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "14.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:retail_returns_management"
},
{
"cpes": [
"cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.4.0"
},
{
"last_affected": "14.1.1.0.0"
}
],
"source": "CPE_FIELD",
"vendor_product": "oracle:weblogic_server"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.13"
}
],
"source": "CPE_FIELD",
"cpe": "cpe:2.3:a:apache:batik:*:*:*:*:*:*:*:*"
}