Code Injection in Batik XML - CVE-2022-41704
Published: October 30, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure processing links to .jar files inside .svg images. A remote attacker can upload a malicious .svg image that contains links to .jar files and execute arbitrary Java code on the system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Code injection example:
<script type="application/java-archive" xlink:href="file.jar"/>
Affected software
Amazon Linux AMI
Debian Linux
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Real Time 15
Ubuntu
Development Tools Module
openSUSE Leap
openEuler
IBM Business Automation Workflow
Confluence Data Center
Jira Software Data Center
Confluence Server
Jira Software Server
IBM Case Manager
IBM Qradar SIEM
libbatik-java (Ubuntu package)
batik
batik-help
batik (Debian package)
dev-java/batik
xmlgraphics-batik
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-demo
xmlgraphics-batik-css
xmlgraphics-batik-rasterizer
xmlgraphics-batik-slideshow
xmlgraphics-batik-javadoc
xmlgraphics-batik-squiggle
xmlgraphics-batik-svgpp
Red Hat Camel for Spring Boot
Fuse
How to mitigate CVE-2022-41704
Confluence Data Center - update to 7.19.16
Confluence Server - update to 7.19.16
Jira Software Data Center - update to 9.4.16
Jira Software Server - update to 9.4.16
libbatik-java (Ubuntu package) - addressed in versions Ubuntu Pro, 1.10-2~18.04.1, 1.12-1ubuntu0.1, 1.14-1ubuntu0.2, 1.14-2ubuntu0.1
batik - update to 1.7-10.10
batik - update to 1.10-7
batik-help - update to 1.10-7
batik (Debian package) - update to 1.12-4+deb11u1
dev-java/batik - update to 1.17
xmlgraphics-batik - addressed in versions 1.17-2.7.1, 1.17-150200.4.7.1
xmlgraphics-batik-ttf2svg - update to 1.17-150200.4.7.1
xmlgraphics-batik-demo - update to 1.17-150200.4.7.1
xmlgraphics-batik-css - update to 1.17-150200.4.7.1
xmlgraphics-batik-rasterizer - update to 1.17-150200.4.7.1
xmlgraphics-batik-slideshow - update to 1.17-150200.4.7.1
xmlgraphics-batik-javadoc - update to 1.17-150200.4.7.1
xmlgraphics-batik-squiggle - update to 1.17-150200.4.7.1
xmlgraphics-batik-svgpp - update to 1.17-150200.4.7.1
Red Hat Camel for Spring Boot - update to 3.20.1
IBM Case Manager - update to 5.3.3-IF011
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
Fuse - update to 7.12.0
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache Batik XML
- Debian update for batik
- Amazon Linux AMI update for batik
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot
- Ubuntu update for batik
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Business Automation Workflow and IBM Case Manager
- Multiple vulnerabilities in Confluence Data Center and Server
- Gentoo update for Apache Batik
- SUSE update for xmlgraphics-batik
- SUSE update for xmlgraphics-batik
- openEuler 22.03 LTS SP1 update for batik
- openEuler 22.03 LTS update for batik
- openEuler 20.03 LTS SP3 update for batik
- openEuler 20.03 LTS SP1 update for batik
- Jira Software Data Center and Server update for Apache batik-bridge
- Multiple vulnerabilities in Fuse 7