CVE-2020-11987: Apache Batik

High severity, CVSS 8.2. EPSS: 13.3% chance of exploitation in the next 30 days.

Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

Affected products

  • Apache Batik: up to and including 1.13
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 33 only; version 34 only
  • Oracle Agile Engineering Data Management: version 6.2.1.0 only
  • Oracle Banking Apis: version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only; version 21.1 only
  • Oracle Banking Digital Experience: version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only; version 21.1 only
  • Oracle Communications Application Session Controller: version 3.9m0p3 only
  • Oracle Communications Metasolv Solution: version 6.3.0 only; version 6.3.1 only
  • Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
  • Oracle Enterprise Repository: version 11.1.1.7.0 only
  • Oracle Flexcube Universal Banking: from 14.1.0, up to and including 14.4.0
  • Oracle Fusion Middleware Mapviewer: version 12.2.1.4.0 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Insurance Policy Administration: from 11.0, up to and including 11.3.1
  • Oracle Product Lifecycle Analytics: version 3.6.1 only
  • Oracle Retail Back Office: version 14.1 only
  • Oracle Retail Central Office: version 14.1 only
  • Oracle Retail Order Broker: version 15.0 only; version 16.0 only
  • Oracle Retail Order Management System Cloud Service: version 19.5 only
  • Oracle Retail Point-Of-Service: version 14.1 only
  • Oracle Retail Returns Management: version 14.1 only
  • Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 14.1.1.0.0 only

Published 2021-02-24. Last modified 2026-10-08.