CVE-2018-8013: Apache Batik

Critical severity, CVSS 9.8. EPSS: 18.9% chance of exploitation in the next 30 days.

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

Affected products

  • Apache Batik: from 1.0, before 1.10 (fixed in 1.10)
  • Canonical Ubuntu Linux: version 14.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Oracle Business Intelligence: version 11.1.1.7.0 only; version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Diameter Signaling Router: before 8.3 (fixed in 8.3)
  • Oracle Communications Metasolv Solution: version 6.3.0 only
  • Oracle Communications WebRTC Session Controller: before 7.2 (fixed in 7.2)
  • Oracle Data Integrator: version 12.2.1.3.0 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only; version 12.1.3.0.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3.0.0, up to and including 7.3.3.0.2; from 8.0.0.0.0, up to and including 8.0.7.1.0
  • Oracle Fusion Middleware Mapviewer: version 12.2.1.2 only; version 12.2.1.3 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Insurance Calculation Engine: version 10.1.1 only; version 10.2.1 only
  • Oracle Insurance Policy Administration j2ee: version 10.0 only; version 10.2 only
  • Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
  • Oracle Retail Back Office: version 13.3 only; version 13.4 only; version 14 only; version 14.1 only
  • Oracle Retail Central Office: version 14.1 only
  • Oracle Retail Integration Bus: version 17.0 only
  • Oracle Retail Order Broker: version 5.1 only; version 5.2 only; version 15.0 only; version 16.0 only
  • Oracle Retail Point-Of-Service: version 13.4 only; version 14.0 only; version 14.1 only
  • Oracle Retail Returns Management: version 14.1 only

Published 2018-05-24. Last modified 2026-06-17.