In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade batik | Feb 19, 2019 | May 24, 2018 |
| Gentoo Linux | — | Upgrade dev-java/batik. | Jan 8, 2024 | May 24, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 24, 2018 |
| Ubuntu | — | Upgrade libbatik-java | Jun 6, 2018 | May 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub