Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2019-17566

 

Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2019-17566

Published: June 16, 2020


Vulnerability identifier: #VU29068
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-17566
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Apache Batik
Oracle Hospitality OPERA 5
Oracle Enterprise Repository
Oracle Fusion Middleware MapViewer
Gentoo Linux
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
SUSE Linux
Opensuse
Fedora
IBM Business Automation Workflow
Oracle Communications Application Session Controller
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Financial Reporting
Oracle Retail Order Broker
Oracle Communications MetaSolv Solution
Oracle Communications Offline Mediation Controller
JD Edwards EnterpriseOne Tools
IBM Tivoli Network Manager (ITNM)
Oracle API Gateway
Oracle Retail Integration Bus
Instantis EnterpriseTrack
libbatik-java (Ubuntu package)
eclipse-mpc
batik
eclipse-m2e-core
dev-java/batik
xmlgraphics-batik
univocity-parsers
eclipse-emf
eclipse-remote
eclipse-gef
eclipse-ecf
eclipse-webtools
eclipse-mylyn
ecj
eclipse
lucene
jetty
eclipse-cdt
IBM Case Manager
Jazz Reporting Service

Detailed vulnerability description

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of "xlink:href" attributes. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


How to mitigate CVE-2019-17566

Install updates from vendor's website.

Sources