CVE-2019-17566Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
CWE-918 · Server-side request forgeryCWE-20 · Improper input validation
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 5 years.
CVSS E:U
A Waratek agent blocks this today.
Applicable rule: A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Improper Input Validation Security Rule.
| Decided by | manual-classification : A researcher's recorded decision for this specific CVE |
|---|---|
| Finding | A researcher classified this CVE as MITIGATED-BY-SECURE-RULE, protected by the ARMR Improper Input Validation Security Rule. |
Written by a Waratek engineer reviewing this CVE. A written classification sets the status directly, ahead of every automated scope rule except a withdrawal.
Rule Name: Improper Input Validation Security Rule
This feature is no available on agent 16.3.x which the customer is on. It is avalible on agent 19.0.0+
app("HTTP Input Validation mod"):
requires(version: ARMR/2.8)
http("HTTP single parameter validation"):
request(paths: "/spiracle/xss.jsp")
validate(parameters: ["number"], is: [integer])
protect(message: "number parameter was not an integer", severity: 5)
endhttp
endapp
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
NVD | Primary | published |
| CVSS 2.0 | 5.0 | no band published | AV:N/AC:L/Au:N/C:N/I:P/A:N |
NVD | Primary |
| Advisory | Type | Quarter | Products Oracle named in risk matrix |
|---|---|---|---|
| Oracle Critical Patch Update January 2022 ↗ | CPU | 2022-Q1 | Oracle Fusion Middleware / Analytics Web Answers (Apache Batik) (5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0, 12.2.1.4.0) |
| Oracle Critical Patch Update July 2021 ↗ | CPU | 2021-Q3 | Oracle Communications Applications / CN OCOMC (Apache Batik) (12.0.0.3.0) Oracle Hyperion / Installation (Apache Batik) (11.1.2.4, 11.2.5.0) |
| Oracle Critical Patch Update April 2021 ↗ | CPU | 2021-Q2 | Oracle Financial Services Applications / Rate Management (Apache Batik) (8.0.6-8.1.0) Oracle Fusion Middleware / Install (Apache Batik) (12.2.1.4.0) Oracle Fusion Middleware / Oracle API Gateway (Apache Batik) (11.1.2.4.0) Oracle Hospitality Applications / Integration (Apache Batik) (5.5, 5.6) Oracle JD Edwards / Web Runtime (Apache Batik) (Prior to 9.2.4.0) |
| Oracle Critical Patch Update January 2021 ↗ | CPU | 2021-Q1 | Oracle Communications / Core (Apache Batik) (3.9m0p2) Oracle Communications Applications / Print Preview (Apache Batik) (6.3.0-6.3.1) Oracle Construction and Engineering / Dashboard module (Apache Batik) (17.1-17.3) Oracle Fusion Middleware / Security Subsystem (Apache Batik) (11.1.1.7.0) Oracle Retail Applications / RIB Kernal (Apache Batik) (15.0.3) Oracle Retail Applications / System Administration (Apache Batik) (15.0, 16.0) |
| Family | Component | Oracle's version cell (verbatim) | Indexed as |
|---|---|---|---|
| Oracle Communications | Core (Apache Batik) | 3.9m0p2 | 3.9.0.2 |
| Oracle Communications Applications | CN OCOMC (Apache Batik) | 12.0.0.3.0 | 12.0.0.3.0 |
| Oracle Communications Applications | Print Preview (Apache Batik) | 6.3.0-6.3.1 | |
| Oracle Construction and Engineering | Dashboard module (Apache Batik) | 17.1-17.3 | |
| Oracle Financial Services Applications | Rate Management (Apache Batik) | 8.0.6-8.1.0 | |
| Oracle Fusion Middleware | Analytics Web Answers (Apache Batik) | 5.5.0.0.0, 5.9.0.0.0, 12.2.1.3.0, 12.2.1.4.0 | 5.5.0.0.0 · 5.9.0.0.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| Oracle Fusion Middleware | Install (Apache Batik) | 12.2.1.4.0 | 12.2.1.4.0 |
| Oracle Fusion Middleware | Oracle API Gateway (Apache Batik) | 11.1.2.4.0 | 11.1.2.4.0 |
| Oracle Fusion Middleware | Security Subsystem (Apache Batik) | 11.1.1.7.0 | 11.1.1.7.0 |
| Oracle Hospitality Applications | Integration (Apache Batik) | 5.5, 5.6 | 5.5 · 5.6 |
| Oracle Hyperion | Installation (Apache Batik) | 11.1.2.4, 11.2.5.0 | 11.1.2.4 · 11.2.5.0 |
| Oracle JD Edwards | Web Runtime (Apache Batik) | Prior to 9.2.4.0 | |
| Oracle Retail Applications | RIB Kernal (Apache Batik) | 15.0.3 | 15.0.3 |
| Oracle Retail Applications | System Administration (Apache Batik) | 15.0, 16.0 | 15.0 · 16.0 |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.apache.xmlgraphics:batik |
0 | 1.13 |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | apache | batik | generic | < 1.13 |
| nvd | oracle | api gateway | generic | 11.1.2.4.0 |
| nvd | oracle | business intelligence | generic | 5.5.0.0.0 · 5.9.0.0.0 · 12.2.1.3.0 · 12.2.1.4.0 |
| nvd | oracle | communications application session controller | generic | 3.9m0p2 |
| nvd | oracle | communications metasolv solution | generic | ≥ 6.3.0 and ≤ 6.3.1 |
| nvd | oracle | communications offline mediation controller | generic | 12.0.0.3.0 |
| nvd | oracle | enterprise repository | generic | 11.1.1.7.0 |
| nvd | oracle | financial services analytical applications infrastructure | generic | ≥ 8.0.6 and ≤ 8.1.0 |
| nvd | oracle | fusion middleware mapviewer | generic | 12.2.1.4.0 |
| nvd | oracle | hospitality opera 5 | generic | 5.5 · 5.6 |
| nvd | oracle | hyperion financial reporting | generic | 11.1.2.4 · 11.2.5.0 |
| nvd | oracle | instantis enterprisetrack | generic | ≥ 17.1 and ≤ 17.3 |
| nvd | oracle | jd edwards enterpriseone tools | generic | < 9.2.4.0 · 9.2.4.2 |
| nvd | oracle | retail integration bus | generic | 15.0.3 |
| nvd | oracle | retail order broker | generic | 15.0 · 16.0 |
| nvd | oracle | retail order management system cloud service | generic | 19.5 |
| nvd | oracle | retail point-of-service | generic | 14.1 |
| nvd | oracle | retail returns management | generic | 14.1 |
| osv | org.apache.xmlgraphics | batik | generic | < 1.13 |
A reviewer manually classified this CVE. The retained record includes the labels and products below, but not the reviewer's reasoning.
## Manual Classification Context **Labels:** HTTP, DASHBOARD MODULE (APACHE BATIK), SECURITY SUBSYSTEM (APACHE BATIK), PRINT PREVIEW (APACHE BATIK), SYSTEM ADMINISTRATION (APACHE BATIK), INTEGRATION (APACHE BATIK), WEB RUNTIME (APACHE BATIK), CORE (APACHE BATIK), RATE MANAGEMENT (APACHE BATIK), NO AUTH REMOTE EXPLOIT, INSTALL (APACHE BATIK), ANALYTICS WEB ANSWERS (APACHE BATIK), ORACLE API GATEWAY (APACHE BATIK), RIB KERNAL (APACHE BATIK), INSTALLATION (APACHE BATIK), CN OCOMC (APACHE BATIK) **Products:** BATIK, HYPERION FINANCIAL REPORTING, ORACLE HOSPITALITY OPERA 5, ORACLE HOSPITALITY APPLICATIONS, ORACLE FUSION MIDDLEWARE, ORACLE FINANCIAL SERVICES APPLICATIONS, ORACLE ENTERPRISE REPOSITORY, ORACLE RETAIL INTEGRATION BUS, ORACLE COMMUNICATIONS, ORACLE COMMUNICATIONS METASOLV SOLUTION, INSTANTIS ENTERPRISETRACK, ORACLE RETAIL APPLICATIONS, ORACLE FINANCIAL SERVICES ANALYTICAL APPLICATIONS INFRASTRUCTURE, ORACLE RETAIL ORDER BROKER, ORACLE HYPERION, ORACLE API GATEWAY, ORACLE CONSTRUCTION AND ENGINEERING, ORACLE FUSION MIDDLEWARE MAPVIEWER, ORACLE JD EDWARDS, ORACLE COMMUNICATIONS APPLICATIONS, JD EDWARDS ENTERPRISEONE TOOLS, ORACLE COMMUNICATIONS APPLICATION SESSION CONTROLLER, ORACLE COMMUNICATIONS OFFLINE MEDIATION CONTROLLER, ORACLE BUSINESS INTELLIGENCE ENTERPRISE EDITION
| Published | 2020-11-12 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |
| Classification created | 2026-09-14 | First commit adding this CVE's research note. |
| Last VRT activity | 2026-09-14 | Most recent commit touching this CVE's classification, patch or rule file. |