Batik

Vendor:

First CVE: Mar 14, 2005 · Active for 21 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 41% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Batik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2005
21 years ago
Most Recent CVE
Oct 25, 2022
1,368 days ago

CVE Severity & Scoring

Batik11 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (81.8%)
Unknown2 (18.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High0 (0.0%)
Unknown2 (18.2%)
User Interaction
None8 (72.7%)
Unknown2 (18.2%)
Required1 (9.1%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None8 (72.7%)
Unknown2 (18.2%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no
May 24, 20189.839NONO
XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause
Mar 24, 20156.430NONO
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker co
Nov 12, 20207.529NONO
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could
Feb 24, 20218.228NONO
A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended t
Oct 25, 20227.527NONO
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.
Sep 22, 20227.527NONO
A vulnerability in Batik of Apache XML Graphics allows an attacker to run Java code from untrusted SVG via JavaScript. This issue affects Apache XML Graphics prior to 1.16. Users a
Oct 25, 20227.525NONO
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types th
Apr 18, 20177.322NONO
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to fetch external resources. This issue affects Apache XML Graphics Batik 1.14.
Sep 22, 20225.321NONO
Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to load a url thru the jar protocol. This issue affects Apache XML Graphics Bati
Sep 22, 20225.321NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Batik

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.1436.03.4%00