// For flags

CVE-2018-8013

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

En Apache Batik en versiones 1.x anteriores a la 1.10, cuando se deserializa la subclase de "AbstractDocument", la clase toma una cadena de inputStream como el nombre de clase y lo emplea para llamar al constructor no-arg de la clase. La soluciĆ³n fue comprobar el tipo de clase antes de llamar a newInstance durante la deserializaciĆ³n.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-03-09 CVE Reserved
  • 2018-05-24 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-11-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
References (17)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Apache
Search vendor "Apache"
Batik
Search vendor "Apache" for product "Batik"
>= 1.0 < 1.10
Search vendor "Apache" for product "Batik" and version " >= 1.0 < 1.10"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
7.0
Search vendor "Debian" for product "Debian Linux" and version "7.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
9.0
Search vendor "Debian" for product "Debian Linux" and version "9.0"
-
Affected
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
14.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "14.04"
lts
Affected
Oracle
Search vendor "Oracle"
Business Intelligence
Search vendor "Oracle" for product "Business Intelligence"
11.1.1.7.0
Search vendor "Oracle" for product "Business Intelligence" and version "11.1.1.7.0"
enterprise
Affected
Oracle
Search vendor "Oracle"
Business Intelligence
Search vendor "Oracle" for product "Business Intelligence"
11.1.1.9.0
Search vendor "Oracle" for product "Business Intelligence" and version "11.1.1.9.0"
enterprise
Affected
Oracle
Search vendor "Oracle"
Business Intelligence
Search vendor "Oracle" for product "Business Intelligence"
12.2.1.3.0
Search vendor "Oracle" for product "Business Intelligence" and version "12.2.1.3.0"
enterprise
Affected
Oracle
Search vendor "Oracle"
Business Intelligence
Search vendor "Oracle" for product "Business Intelligence"
12.2.1.4.0
Search vendor "Oracle" for product "Business Intelligence" and version "12.2.1.4.0"
enterprise
Affected
Oracle
Search vendor "Oracle"
Communications Diameter Signaling Router
Search vendor "Oracle" for product "Communications Diameter Signaling Router"
< 8.3
Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " < 8.3"
-
Affected
Oracle
Search vendor "Oracle"
Communications Metasolv Solution
Search vendor "Oracle" for product "Communications Metasolv Solution"
6.3.0
Search vendor "Oracle" for product "Communications Metasolv Solution" and version "6.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Communications Webrtc Session Controller
Search vendor "Oracle" for product "Communications Webrtc Session Controller"
< 7.2
Search vendor "Oracle" for product "Communications Webrtc Session Controller" and version " < 7.2"
-
Affected
Oracle
Search vendor "Oracle"
Data Integrator
Search vendor "Oracle" for product "Data Integrator"
12.2.1.3.0
Search vendor "Oracle" for product "Data Integrator" and version "12.2.1.3.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Repository
Search vendor "Oracle" for product "Enterprise Repository"
11.1.1.7.0
Search vendor "Oracle" for product "Enterprise Repository" and version "11.1.1.7.0"
-
Affected
Oracle
Search vendor "Oracle"
Enterprise Repository
Search vendor "Oracle" for product "Enterprise Repository"
12.1.3.0.0
Search vendor "Oracle" for product "Enterprise Repository" and version "12.1.3.0.0"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Analytical Applications Infrastructure
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure"
>= 7.3.3.0.0 <= 7.3.3.0.2
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 7.3.3.0.0 <= 7.3.3.0.2"
-
Affected
Oracle
Search vendor "Oracle"
Financial Services Analytical Applications Infrastructure
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure"
>= 8.0.0.0.0 <= 8.0.7.1.0
Search vendor "Oracle" for product "Financial Services Analytical Applications Infrastructure" and version " >= 8.0.0.0.0 <= 8.0.7.1.0"
-
Affected
Oracle
Search vendor "Oracle"
Fusion Middleware Mapviewer
Search vendor "Oracle" for product "Fusion Middleware Mapviewer"
12.2.1.2
Search vendor "Oracle" for product "Fusion Middleware Mapviewer" and version "12.2.1.2"
-
Affected
Oracle
Search vendor "Oracle"
Fusion Middleware Mapviewer
Search vendor "Oracle" for product "Fusion Middleware Mapviewer"
12.2.1.3
Search vendor "Oracle" for product "Fusion Middleware Mapviewer" and version "12.2.1.3"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.1
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.1"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.2
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.2"
-
Affected
Oracle
Search vendor "Oracle"
Instantis Enterprisetrack
Search vendor "Oracle" for product "Instantis Enterprisetrack"
17.3
Search vendor "Oracle" for product "Instantis Enterprisetrack" and version "17.3"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.1.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.1.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Calculation Engine
Search vendor "Oracle" for product "Insurance Calculation Engine"
10.2.1
Search vendor "Oracle" for product "Insurance Calculation Engine" and version "10.2.1"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration J2ee
Search vendor "Oracle" for product "Insurance Policy Administration J2ee"
10.0
Search vendor "Oracle" for product "Insurance Policy Administration J2ee" and version "10.0"
-
Affected
Oracle
Search vendor "Oracle"
Insurance Policy Administration J2ee
Search vendor "Oracle" for product "Insurance Policy Administration J2ee"
10.2
Search vendor "Oracle" for product "Insurance Policy Administration J2ee" and version "10.2"
-
Affected
Oracle
Search vendor "Oracle"
Jd Edwards Enterpriseone Tools
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools"
9.2
Search vendor "Oracle" for product "Jd Edwards Enterpriseone Tools" and version "9.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
13.3
Search vendor "Oracle" for product "Retail Back Office" and version "13.3"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
13.4
Search vendor "Oracle" for product "Retail Back Office" and version "13.4"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14
Search vendor "Oracle" for product "Retail Back Office" and version "14"
-
Affected
Oracle
Search vendor "Oracle"
Retail Back Office
Search vendor "Oracle" for product "Retail Back Office"
14.1
Search vendor "Oracle" for product "Retail Back Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Central Office
Search vendor "Oracle" for product "Retail Central Office"
14.1
Search vendor "Oracle" for product "Retail Central Office" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Integration Bus
Search vendor "Oracle" for product "Retail Integration Bus"
17.0
Search vendor "Oracle" for product "Retail Integration Bus" and version "17.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.1
Search vendor "Oracle" for product "Retail Order Broker" and version "5.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
5.2
Search vendor "Oracle" for product "Retail Order Broker" and version "5.2"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
15.0
Search vendor "Oracle" for product "Retail Order Broker" and version "15.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Order Broker
Search vendor "Oracle" for product "Retail Order Broker"
16.0
Search vendor "Oracle" for product "Retail Order Broker" and version "16.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-service
Search vendor "Oracle" for product "Retail Point-of-service"
13.4
Search vendor "Oracle" for product "Retail Point-of-service" and version "13.4"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-service
Search vendor "Oracle" for product "Retail Point-of-service"
14.0
Search vendor "Oracle" for product "Retail Point-of-service" and version "14.0"
-
Affected
Oracle
Search vendor "Oracle"
Retail Point-of-service
Search vendor "Oracle" for product "Retail Point-of-service"
14.1
Search vendor "Oracle" for product "Retail Point-of-service" and version "14.1"
-
Affected
Oracle
Search vendor "Oracle"
Retail Returns Management
Search vendor "Oracle" for product "Retail Returns Management"
14.1
Search vendor "Oracle" for product "Retail Returns Management" and version "14.1"
-
Affected