Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-44730

 

Server-Side Request Forgery (SSRF) in Apache Batik - CVE-2022-44730

Published: August 25, 2023


Vulnerability identifier: #VU80019
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2022-44730
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote user to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when parsing SVG images. A remote user can upload a malicious SVG image and trick the application to initiate requests to arbitrary systems.

Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.


Affected software

Apache Batik
IBM Integration Bus
IBM Business Automation Workflow
IBM Intelligent Operations Center
IBM Maximo Asset Management
IBM Cloud Application Performance Management (APM)
IBM Maximo Application Suite
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
Development Tools Module
openSUSE Leap
openEuler
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
dev-java/batik
batik-help
batik
xmlgraphics-batik
xmlgraphics-batik-demo
xmlgraphics-batik-css
xmlgraphics-batik-rasterizer
xmlgraphics-batik-slideshow
xmlgraphics-batik-javadoc
xmlgraphics-batik-squiggle
xmlgraphics-batik-ttf2svg
xmlgraphics-batik-svgpp
Red Hat Camel for Spring Boot
IBM App Connect Enterprise
Engineering Test Management
IBM Business Automation Manager Open Editions
IBM Engineering Systems Design Rhapsody

How to mitigate CVE-2022-44730

Install updates from vendor's website.

Apache Batik - update to 1.17
IBM Intelligent Operations Center - update to 5.2.5
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF02
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.13.5
dev-java/batik - update to 1.17
batik-help - update to 1.17-1
batik - update to 1.17-1
xmlgraphics-batik - addressed in versions 1.17-2.7.1, 1.17-150200.4.7.1
xmlgraphics-batik-demo - update to 1.17-150200.4.7.1
xmlgraphics-batik-css - update to 1.17-150200.4.7.1
xmlgraphics-batik-rasterizer - update to 1.17-150200.4.7.1
xmlgraphics-batik-slideshow - update to 1.17-150200.4.7.1
xmlgraphics-batik-javadoc - update to 1.17-150200.4.7.1
xmlgraphics-batik-squiggle - update to 1.17-150200.4.7.1
xmlgraphics-batik-ttf2svg - update to 1.17-150200.4.7.1
xmlgraphics-batik-svgpp - update to 1.17-150200.4.7.1
Red Hat Camel for Spring Boot - update to 4.0.0
Engineering Test Management - addressed in versions 7.0.1.0.23, 7.0.2.0.25
IBM Maximo Asset Management - addressed in versions 7.6.1.2.40, 7.6.1.3.15
IBM Business Automation Manager Open Editions - update to 8.0.5
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Maximo Application Suite - addressed in versions 8.6.8, 8.7.3
IBM Engineering Systems Design Rhapsody - addressed in versions 9.0.1.0.6, 9.0.2.0.2
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.0

External References

Related Security Bulletins