Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16.
On version 1.16, a malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. Users are recommended to upgrade to version 1.17 or later.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade batik-javadocUpgrade batik-ttf2svgUpgrade batik-demoUpgrade batik-squiggleUpgrade batik-slideshowUpgrade batikUpgrade batik-svgppUpgrade batik-rasterizer | Mar 26, 2025 | Aug 22, 2023 |
| Debian | — | Upgrade batik | Oct 16, 2023 | Aug 22, 2023 |
| Gentoo Linux | — | Upgrade dev-java/batik. | Jan 8, 2024 | Aug 22, 2023 |
| Oracle Missing Cpu Oct 2023 | — | Apply the October 2023 Critical Patch Update (CPU) for Oracle Database | Oct 18, 2023 | Aug 22, 2023 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 35893811 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 35904051 for version 14.1.1.0.0. | Oct 19, 2023 | Aug 22, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 22, 2023 |
| Suse | — | Upgrade xmlgraphics-batik-demoUpgrade xmlgraphics-batik-squiggleUpgrade xmlgraphics-batik-svgppUpgrade xmlgraphics-batik-slideshowUpgrade xmlgraphics-batik-ttf2svgUpgrade xmlgraphics-batik-javadocUpgrade xmlgraphics-batik-rasterizerUpgrade xmlgraphics-batikUpgrade xmlgraphics-batik-css | Aug 9, 2024 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub