XXE attack in Apache Batik - CVE-2017-5662

 

XXE attack in Apache Batik - CVE-2017-5662

Published: June 5, 2018


Vulnerability identifier: #VU13180
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5662
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated attacker to conduct XXE-attack on the target system.

The weakness exists due to improper restriction of XML external entity references. A remote attacker can supply specially crafted xml document to gain access to arbitrary files or conduct amplification attack to cause the service to crash.

Affected software

Apache Batik
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Ubuntu
Fedora
batik
xmlgraphics-batik
IBM Tivoli Network Manager (ITNM)
IBM Intelligent Operations Center
IBM Cloud Application Performance Management (APM)
IBM Engineering Systems Design Rhapsody

How to mitigate CVE-2017-5662

Update to version 1.9.

batik - addressed in versions 1.8-9.fc24, 1.8-9.fc25, 1.9-3.fc26
xmlgraphics-batik - update to 1.17-2.7.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Intelligent Operations Center - update to 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5

External References

Related Security Bulletins