CVE-2018-8013: Apache Batik
Critical severity, CVSS 9.8. EPSS: 18.9% chance of exploitation in the next 30 days.
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Affected products
- Apache Batik: from 1.0, before 1.10 (fixed in 1.10)
- Canonical Ubuntu Linux: version 14.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Oracle Business Intelligence: version 11.1.1.7.0 only; version 11.1.1.9.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Communications Diameter Signaling Router: before 8.3 (fixed in 8.3)
- Oracle Communications Metasolv Solution: version 6.3.0 only
- Oracle Communications WebRTC Session Controller: before 7.2 (fixed in 7.2)
- Oracle Data Integrator: version 12.2.1.3.0 only
- Oracle Enterprise Repository: version 11.1.1.7.0 only; version 12.1.3.0.0 only
- Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3.0.0, up to and including 7.3.3.0.2; from 8.0.0.0.0, up to and including 8.0.7.1.0
- Oracle Fusion Middleware Mapviewer: version 12.2.1.2 only; version 12.2.1.3 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle Insurance Calculation Engine: version 10.1.1 only; version 10.2.1 only
- Oracle Insurance Policy Administration j2ee: version 10.0 only; version 10.2 only
- Oracle Jd Edwards Enterpriseone Tools: version 9.2 only
- Oracle Retail Back Office: version 13.3 only; version 13.4 only; version 14 only; version 14.1 only
- Oracle Retail Central Office: version 14.1 only
- Oracle Retail Integration Bus: version 17.0 only
- Oracle Retail Order Broker: version 5.1 only; version 5.2 only; version 15.0 only; version 16.0 only
- Oracle Retail Point-Of-Service: version 13.4 only; version 14.0 only; version 14.1 only
- Oracle Retail Returns Management: version 14.1 only
Published 2018-05-24. Last modified 2026-06-17.