Server-Side Request Forgery (SSRF) in Apache XML Graphics Commons - CVE-2020-11988
Published: June 21, 2021
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input within the XMPParser in Apache XmlGraphics Commons. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
IBM Business Automation Workflow
Dell Secure Connect Gateway
IBM Intelligent Operations Center
Red Hat Decision Manager
Oracle Financial Services Revenue Management and Billing
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
openEuler
Fedora
xmlgraphics-commons
IBM TRIRIGA Application Platform
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM Case Manager
Jazz Reporting Service
Fuse
How to mitigate CVE-2020-11988
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Intelligent Operations Center - update to 5.2.4
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.11.0
Red Hat Decision Manager - update to 7.11.0
xmlgraphics-commons - update to 2.2-4
xmlgraphics-commons - addressed in versions 2.6-1.fc33, 2.6-1.fc34
xmlgraphics-commons - update to 2.6-3.3.1
IBM TRIRIGA Application Platform - update to 4.5
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix021
Fuse - update to 7.10.0
External References
- https://lists.apache.org/thread.html/r2877ae10e8be56a3c52d03e373512ddd32f16b863f24c2e22f5a5ba2@%3Cdev.poi.apache.org%3E
- https://lists.apache.org/thread.html/r588d05a0790b40a0eb81088252e1e8c1efb99706631421f17038eb05@%3Cdev.poi.apache.org%3E
- https://lists.apache.org/thread.html/ra8f4d6ae402ec020ee3e8c28632c91be131c4d8b4c9c6756a179b12b@%3Cdev.jmeter.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/22HESSYU7T4D6GGENUVEX3X3H6FGBECH/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JP4XA56DA3BFNRBBLBXM6ZAI5RUVFA33/
- https://xmlgraphics.apache.org/security.html
Related Security Bulletins
- SSRF in Apache XmlGraphics Commons
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Multiple vulnerabilities in Red Hat Decision Manager
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- SUSE update for xmlgraphics-commons
- Multiple vulnerabilities in Oracle Financial Services Revenue Management and Billing
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Server-Side Request Forgery (SSRF) in IBM Intelligent Operations Center
- Server-Side Request Forgery (SSRF) in IBM Jazz Reporting Service
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Server-Side Request Forgery (SSRF) in IBM TRIRIGA Application Platform
- openEuler update for xmlgraphics-commons
- Multiple vulnerabilities in Fuse 7.10
- Fedora 34 update for xmlgraphics-commons
- Fedora 33 update for xmlgraphics-commons
- Multiple vulnerabilities in Oracle Financial Services Analytical Applications Infrastructure