Input validation error in Apache Batik - CVE-2015-0250
Published: July 14, 2023
Vulnerability identifier: #VU78255
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-0250
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can read arbitrary files or cause a denial of service via a crafted SVG file.
Affected software
Apache Batik
IBM Sterling Order Management
IBM Engineering Systems Design Rhapsody
Fedora
batik
IBM Tivoli Network Manager (ITNM)
IBM Intelligent Operations Center
IBM Cloud Application Performance Management (APM)
IBM Sterling Order Management
IBM Engineering Systems Design Rhapsody
Fedora
batik
IBM Tivoli Network Manager (ITNM)
IBM Intelligent Operations Center
IBM Cloud Application Performance Management (APM)
How to mitigate CVE-2015-0250
Cybersecurity Help is currently unaware of any official solution to address this vulnerability..
Apache Batik - update to 1.8
batik - addressed in versions 1.8-0.18.svn1230816.fc21, 1.8-0.18.svn1230816.fc22
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Intelligent Operations Center - update to 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
batik - addressed in versions 1.8-0.18.svn1230816.fc21, 1.8-0.18.svn1230816.fc22
IBM Tivoli Network Manager (ITNM) - update to 4.2.0.16
IBM Intelligent Operations Center - update to 5.2.4
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Engineering Systems Design Rhapsody - update to 9.0.1.0.5
External References
- http://advisories.mageia.org/MGASA-2015-0138.html
- http://packetstormsecurity.com/files/130964/Apache-Batik-XXE-Injection.html
- http://rhn.redhat.com/errata/RHSA-2016-0041.html
- http://rhn.redhat.com/errata/RHSA-2016-0042.html
- http://seclists.org/fulldisclosure/2015/Mar/142
- http://www.debian.org/security/2015/dsa-3205
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:203
- http://www.securitytracker.com/id/1032781
- http://www.ubuntu.com/usn/USN-2548-1
- http://www-01.ibm.com/support/docview.wss?uid=swg21963275
- http://xmlgraphics.apache.org/security.html
Related Security Bulletins
- Multiple vulnerabilities in IBM Engineering Systems Design Rhapsody
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)
- Multiple vulnerabilities in IBM Tivoli Network Manager (ITNM)
- Multiple vulnerabilities in IBM Application Performance Management
- Input validation error in IBM Sterling Order Management
- Fedora 22 update for batik
- Fedora 21 update for batik