Server-Side Request Forgery (SSRF) in Apache XML Graphics Commons - CVE-2020-11988

 

Server-Side Request Forgery (SSRF) in Apache XML Graphics Commons - CVE-2020-11988

Published: June 21, 2021


Vulnerability identifier: #VU54291
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11988
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input within the XMPParser in Apache XmlGraphics Commons. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Apache XML Graphics Commons
IBM Business Automation Workflow
Dell Secure Connect Gateway
IBM Intelligent Operations Center
Red Hat Decision Manager
Oracle Financial Services Revenue Management and Billing
Oracle Business Intelligence Enterprise Edition
Oracle Financial Services Analytical Applications Infrastructure
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
openEuler
Fedora
xmlgraphics-commons
IBM TRIRIGA Application Platform
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
IBM Case Manager
Jazz Reporting Service
Fuse

How to mitigate CVE-2020-11988

Install updates from vendor's website.

Apache XML Graphics Commons - update to 2.6
Dell Secure Connect Gateway - update to 5.12.00.10
IBM Intelligent Operations Center - update to 5.2.4
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.11.0
Red Hat Decision Manager - update to 7.11.0
xmlgraphics-commons - update to 2.2-4
xmlgraphics-commons - addressed in versions 2.6-1.fc33, 2.6-1.fc34
xmlgraphics-commons - update to 2.6-3.3.1
IBM TRIRIGA Application Platform - update to 4.5
EMC ViPR SRM - update to 4.9.0.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.9.0.0
IBM Case Manager - update to 5.3.3-IF011
Jazz Reporting Service - update to 7.0.2 iFix021
Fuse - update to 7.10.0

External References

Related Security Bulletins