CVE-2019-17566: Apache Batik

High severity, CVSS 7.5. EPSS: 10.9% chance of exploitation in the next 30 days.

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Affected products

  • Apache Batik: before 1.13 (fixed in 1.13)
  • Oracle API Gateway: version 11.1.2.4.0 only
  • Oracle Business Intelligence: version 5.5.0.0.0 only; version 5.9.0.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Application Session Controller: version 3.9m0p2 only
  • Oracle Communications Metasolv Solution: from 6.3.0, up to and including 6.3.1
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
  • Oracle Fusion Middleware Mapviewer: version 12.2.1.4.0 only
  • Oracle Hospitality Opera 5: version 5.5 only; version 5.6 only
  • Oracle Hyperion Financial Reporting: version 11.1.2.4 only; version 11.2.5.0 only
  • Oracle Instantis Enterprisetrack: from 17.1, up to and including 17.3
  • Oracle Jd Edwards Enterpriseone Tools: before 9.2.4.0 (fixed in 9.2.4.0); version 9.2.4.2 only
  • Oracle Retail Integration Bus: version 15.0.3 only
  • Oracle Retail Order Broker: version 15.0 only; version 16.0 only
  • Oracle Retail Order Management System Cloud Service: version 19.5 only
  • Oracle Retail Point-Of-Service: version 14.1 only
  • Oracle Retail Returns Management: version 14.1 only

Published 2020-11-12. Last modified 2026-06-17.