XXE attack in Apache Batik - CVE-2017-5662
Published: June 5, 2018
Vulnerability identifier: #VU13180
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-5662
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to conduct XXE-attack on the target system.
The weakness exists due to improper restriction of XML external entity references. A remote attacker can supply specially crafted xml document to gain access to arbitrary files or conduct amplification attack to cause the service to crash.
The weakness exists due to improper restriction of XML external entity references. A remote attacker can supply specially crafted xml document to gain access to arbitrary files or conduct amplification attack to cause the service to crash.
Affected software
Apache Batik
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Ubuntu
Fedora
batik
xmlgraphics-batik
IBM Tivoli Network Manager (ITNM)
IBM Intelligent Operations Center
IBM Cloud Application Performance Management (APM)
IBM Engineering Systems Design Rhapsody
Debian Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Ubuntu
Fedora
batik
xmlgraphics-batik
IBM Tivoli Network Manager (ITNM)
IBM Intelligent Operations Center
IBM Cloud Application Performance Management (APM)
IBM Engineering Systems Design Rhapsody
How to mitigate CVE-2017-5662
Update to version 1.9.
batik - addressed in versions 1.8-9.fc24, 1.8-9.fc25, 1.9-3.fc26
xmlgraphics-batik - update to 1.17-2.7.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Intelligent Operations Center - update to 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
xmlgraphics-batik - update to 1.17-2.7.1
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Intelligent Operations Center - update to 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
External References
Related Security Bulletins
- Debian update for batik
- Ubuntu update for Apache Batik
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in IBM Tivoli Network Manager (ITNM)
- Multiple vulnerabilities in IBM Application Performance Management
- SUSE update for xmlgraphics-batik
- Fedora 24 update for batik
- Fedora 25 update for batik
- Fedora 26 update for batik