Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2019-17566
Published: June 16, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of "xlink:href" attributes. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Oracle Hospitality OPERA 5
Oracle Enterprise Repository
Oracle Fusion Middleware MapViewer
Gentoo Linux
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
SUSE Linux
Opensuse
Fedora
IBM Business Automation Workflow
Oracle Communications Application Session Controller
Dell Secure Connect Gateway
IBM Cloud Application Performance Management (APM)
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Financial Reporting
Oracle Retail Order Broker
Oracle Communications MetaSolv Solution
Oracle Communications Offline Mediation Controller
JD Edwards EnterpriseOne Tools
IBM Tivoli Network Manager (ITNM)
Oracle API Gateway
Oracle Retail Integration Bus
Instantis EnterpriseTrack
libbatik-java (Ubuntu package)
eclipse-mpc
batik
eclipse-m2e-core
dev-java/batik
xmlgraphics-batik
univocity-parsers
eclipse-emf
eclipse-remote
eclipse-gef
eclipse-ecf
eclipse-webtools
eclipse-mylyn
ecj
eclipse
lucene
jetty
eclipse-cdt
IBM Case Manager
Jazz Reporting Service
How to mitigate CVE-2019-17566
Dell Secure Connect Gateway - update to 5.12.00.10
JD Edwards EnterpriseOne Tools - update to 9.2.4.0
libbatik-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.14-1ubuntu0.2, 1.14-2ubuntu0.1
eclipse-mpc - update to 1.8.3-2.fc32
batik - update to 1.13-1.fc32
eclipse-m2e-core - update to 1.16.1-1.fc32
dev-java/batik - update to 1.17
xmlgraphics-batik - update to 1.17-2.7.1
univocity-parsers - update to 2.8.4-5.fc32
eclipse-emf - update to 2.22.0-2.fc32
eclipse-remote - update to 3.0.1-6.fc32
eclipse-gef - update to 3.11.0-13.fc32
eclipse-ecf - update to 3.14.8-4.fc32
eclipse-webtools - update to 3.18.0-4.fc32
eclipse-mylyn - update to 3.25.0-3.fc32
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
ecj - update to 4.16-4.fc32
eclipse - update to 4.16-11.fc32
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix021
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
lucene - update to 8.4.1-9.fc32
jetty - update to 9.4.31-2.fc32
eclipse-cdt - update to 9.11.1-8.fc32
External References
Related Security Bulletins
- SSRF in Apache Batik
- OpenSUSE Linux update for xmlgraphics-batik
- OpenSUSE Linux update for xmlgraphics-batik
- Multiple vulnerabilities in Oracle Communications MetaSolv Solution
- Multiple vulnerabilities in Oracle Communications Application Session Controller
- Server-Side Request Forgery (SSRF) in Instantis EnterpriseTrack
- Multiple vulnerabilities in Oracle Enterprise Repository
- Multiple vulnerabilities in Oracle Retail Integration Bus
- Multiple vulnerabilities in Oracle Retail Order Broker
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure
- Multiple vulnerabilities in Oracle Fusion Middleware MapViewer
- Multiple vulnerabilities in Oracle API Gateway
- Multiple vulnerabilities in Oracle Hospitality OPERA 5
- Multiple vulnerabilities in JD Edwards EnterpriseOne Tools
- Multiple vulnerabilities in Oracle Communications Offline Mediation Controller
- Server-Side Request Forgery (SSRF) in Hyperion Financial Reporting
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Ubuntu update for batik
- Multiple vulnerabilities in IBM Tivoli Network Manager (ITNM)
- Server-Side Request Forgery (SSRF) in IBM Jazz Reporting Service
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Server-Side Request Forgery (SSRF) in IBM Application Performance Management products.
- Gentoo update for Apache Batik
- SUSE update for xmlgraphics-batik
- Fedora 32 update for batik, ecj, eclipse, eclipse-cdt, eclipse-ecf, eclipse-emf, eclipse-gef, eclipse-m2e-core, eclipse-mpc, eclipse-mylyn, eclipse-remote, eclipse-webtools, jetty, lucene, univocity-parsers