Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-44729

 

Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-44729

Published: August 25, 2023


Vulnerability identifier: #VU80018
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-44729
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Apache Batik
Oracle Business Process Management Suite
IBM Integration Bus
IBM Business Automation Workflow
Jira Service Management Data Center
Jira Service Management Server
IBM Intelligent Operations Center
Oracle Middleware Common Libraries and Tools
Middleware Common Libraries and Tools
Dell Secure Connect Gateway
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
Development Tools Module
openSUSE Leap
openEuler
Oracle Database Server
Oracle Financial Services Revenue Management and Billing
Oracle Business Intelligence Enterprise Edition
Financial Reporting
Engineering Test Management
IBM Business Automation Manager Open Editions
IBM Engineering Systems Design Rhapsody
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Oracle WebLogic Server
dev-java/batik
batik-help
batik
xmlgraphics-batik
xmlgraphics-batik-rasterizer
xmlgraphics-batik-slideshow
xmlgraphics-batik-javadoc
xmlgraphics-batik-squiggle
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-svgpp
xmlgraphics-batik-css
xmlgraphics-batik-demo
Red Hat Camel for Spring Boot
IBM App Connect Enterprise

How to mitigate CVE-2022-44729

Install updates from vendor's website.

Apache Batik - update to 1.17
Oracle Database Server - update to 19.3
Oracle Financial Services Revenue Management and Billing - update to 3.2.0.0.0
Jira Service Management Data Center - addressed in versions 4.20.30, 5.4.15, 5.12.2
Jira Service Management Server - addressed in versions 4.20.30, 5.4.15, 5.12.2
IBM Intelligent Operations Center - update to 5.2.5
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF02
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF02
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
dev-java/batik - update to 1.17
batik-help - update to 1.17-1
batik - update to 1.17-1
xmlgraphics-batik - addressed in versions 1.17-2.7.1, 1.17-150200.4.7.1
xmlgraphics-batik-rasterizer - update to 1.17-150200.4.7.1
xmlgraphics-batik-slideshow - update to 1.17-150200.4.7.1
xmlgraphics-batik-javadoc - update to 1.17-150200.4.7.1
xmlgraphics-batik-squiggle - update to 1.17-150200.4.7.1
xmlgraphics-batik-ttf2svg - update to 1.17-150200.4.7.1
xmlgraphics-batik-svgpp - update to 1.17-150200.4.7.1
xmlgraphics-batik-css - update to 1.17-150200.4.7.1
xmlgraphics-batik-demo - update to 1.17-150200.4.7.1
Red Hat Camel for Spring Boot - update to 4.0.0
Dell Secure Connect Gateway - update to 5.20.00.10
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.25
IBM Maximo Asset Management - addressed in versions 7.6.1.2.40, 7.6.1.3.15
IBM Business Automation Manager Open Editions - update to 8.0.5
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Maximo Application Suite - addressed in versions 8.6.8, 8.7.3
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.0

External References

Related Security Bulletins