Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-38398
Published: September 22, 2022 / Updated: October 4, 2022
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in DefaultExternalResourceSecurity when handling URLs loaded though jar protocol. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
Affected software
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Ubuntu
openEuler
IBM Business Automation Workflow
IBM Intelligent Operations Center
IBM Integration Bus
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
Maximo Manage Application in IBM Maximo Application Suite
IBM Maximo Application Suite
IBM App Connect Enterprise
Red Hat Camel for Spring Boot
libbatik-java (Ubuntu package)
batik
dev-java/batik
batik-help
xmlgraphics-batik
IBM Case Manager
Jazz Reporting Service
Engineering Test Management
IBM Engineering Systems Design Rhapsody
Fuse
How to mitigate CVE-2022-38398
IBM Intelligent Operations Center - update to 5.2.4
libbatik-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.14-1ubuntu0.2, 1.14-2ubuntu0.1
batik - update to 1.7-10.10
dev-java/batik - update to 1.17
batik-help - update to 1.17-1
batik - update to 1.17-1
xmlgraphics-batik - update to 1.17-2.7.1
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Case Manager - update to 5.3.3-IF011
Engineering Test Management - addressed in versions 7.0.1.0.22, 7.0.2.0.22
Jazz Reporting Service - update to 7.0.2 iFix021
IBM Maximo Asset Management - addressed in versions 7.6.1.2.0.31, 7.6.1.3.0.6
Fuse - update to 7.12.0
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.14
Maximo Manage Application in IBM Maximo Application Suite - update to 8.4.7
IBM Maximo Application Suite - update to 8.8.7
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
External References
Related Security Bulletins
- Multiple SSRF vulnerabilities in Apache Batik
- Amazon Linux AMI update for batik
- Multiple vulnerabilities in IBM Maximo Manage application in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Maximo Asset Management
- Multiple vulnerabilities in IBM Engineering Test Management (ETM)
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot
- Ubuntu update for batik
- Multiple vulnerabilities in IBM App Connect Enterprise Toolkit and the IBM Integration Bus Toolkit
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in IBM Jazz Reporting Service
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in IBM Cloud Application Performance Management (APM)
- Gentoo update for Apache Batik
- SUSE update for xmlgraphics-batik
- openEuler update for batik
- Multiple vulnerabilities in Fuse 7