CVE-2019-17566: Apache Batik
High severity, CVSS 7.5. EPSS: 10.9% chance of exploitation in the next 30 days.
Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected products
- Apache Batik: before 1.13 (fixed in 1.13)
- Oracle API Gateway: version 11.1.2.4.0 only
- Oracle Business Intelligence: version 5.5.0.0.0 only; version 5.9.0.0.0 only; version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Communications Application Session Controller: version 3.9m0p2 only
- Oracle Communications Metasolv Solution: from 6.3.0, up to and including 6.3.1
- Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
- Oracle Enterprise Repository: version 11.1.1.7.0 only
- Oracle Financial Services Analytical Applications Infrastructure: from 8.0.6, up to and including 8.1.0
- Oracle Fusion Middleware Mapviewer: version 12.2.1.4.0 only
- Oracle Hospitality Opera 5: version 5.5 only; version 5.6 only
- Oracle Hyperion Financial Reporting: version 11.1.2.4 only; version 11.2.5.0 only
- Oracle Instantis Enterprisetrack: from 17.1, up to and including 17.3
- Oracle Jd Edwards Enterpriseone Tools: before 9.2.4.0 (fixed in 9.2.4.0); version 9.2.4.2 only
- Oracle Retail Integration Bus: version 15.0.3 only
- Oracle Retail Order Broker: version 15.0 only; version 16.0 only
- Oracle Retail Order Management System Cloud Service: version 19.5 only
- Oracle Retail Point-Of-Service: version 14.1 only
- Oracle Retail Returns Management: version 14.1 only
Published 2020-11-12. Last modified 2026-06-17.