CVE-2020-11987: Apache Batik
High severity, CVSS 8.2. EPSS: 13.3% chance of exploitation in the next 30 days.
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Affected products
- Apache Batik: up to and including 1.13
- Debian Debian Linux: version 10.0 only
- Fedoraproject Fedora: version 33 only; version 34 only
- Oracle Agile Engineering Data Management: version 6.2.1.0 only
- Oracle Banking Apis: version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only; version 21.1 only
- Oracle Banking Digital Experience: version 18.3 only; version 19.1 only; version 19.2 only; version 20.1 only; version 21.1 only
- Oracle Communications Application Session Controller: version 3.9m0p3 only
- Oracle Communications Metasolv Solution: version 6.3.0 only; version 6.3.1 only
- Oracle Communications Offline Mediation Controller: version 12.0.0.3.0 only
- Oracle Enterprise Repository: version 11.1.1.7.0 only
- Oracle Flexcube Universal Banking: from 14.1.0, up to and including 14.4.0
- Oracle Fusion Middleware Mapviewer: version 12.2.1.4.0 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle Insurance Policy Administration: from 11.0, up to and including 11.3.1
- Oracle Product Lifecycle Analytics: version 3.6.1 only
- Oracle Retail Back Office: version 14.1 only
- Oracle Retail Central Office: version 14.1 only
- Oracle Retail Order Broker: version 15.0 only; version 16.0 only
- Oracle Retail Order Management System Cloud Service: version 19.5 only
- Oracle Retail Point-Of-Service: version 14.1 only
- Oracle Retail Returns Management: version 14.1 only
- Oracle WebLogic Server: version 12.2.1.3.0 only; version 12.2.1.4.0 only; version 14.1.1.0.0 only
Published 2021-02-24. Last modified 2026-10-08.