peter bassill · operator
$ cve CVE-2018-8013 JSON

CVE-2018-8013

9.8
CRITICAL · CVSS 3.0 · EPSS 18.9% (pctl 97)

Patch early

EPSS 18.9% — above the 10% action threshold.

Description

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS18.93% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-05-24
Last modified2026-06-17

Affected (21)

VendorProduct
apachebatik
canonicalubuntu linux
debiandebian linux
oraclebusiness intelligence
oraclecommunications diameter signaling router
oraclecommunications metasolv solution
oraclecommunications webrtc session controller
oracledata integrator
oracleenterprise repository
oraclefinancial services analytical applications infrastructure
oraclefusion middleware mapviewer
oracleinstantis enterprisetrack
oracleinsurance calculation engine
oracleinsurance policy administration j2ee
oraclejd edwards enterpriseone tools
oracleretail back office
oracleretail central office
oracleretail integration bus
oracleretail order broker
oracleretail point-of-service
oracleretail returns management

References

→ the Explorer  ·  watch your stack  ·  NVD