In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Batik
APPApache1.0 – 1.10 (excl.)Canonical Ubuntu
OSCanonical14.04Debian
OSDebian7.08.09.0Oracle Business Intelligence
APPOracle11.1.1.7.011.1.1.9.012.2.1.3.012.2.1.4.0Oracle Communications Diameter Signaling Router
APPOracle< 8.3Oracle Communications Metasolv Solution
APPOracle6.3.0Oracle Communications Webrtc Session Controller
APPOracle< 7.2Oracle Data Integrator
APPOracle12.2.1.3.0Oracle Enterprise Repository
APPOracle11.1.1.7.012.1.3.0.0Oracle Financial Services Analytical Applications Infrastructure
APPOracle7.3.3.0.0 – 7.3.3.0.28.0.0.0.0 – 8.0.7.1.0Oracle Fusion Middleware Mapviewer
APPOracle12.2.1.212.2.1.3Oracle Instantis Enterprisetrack
APPOracle17.117.217.3Oracle Insurance Calculation Engine
APPOracle10.1.110.2.1Oracle Insurance Policy Administration J2ee
APPOracle10.010.2Oracle Jd Edwards Enterpriseone Tools
APPOracle9.2Oracle Retail Back Office
APPOracle13.313.41414.1Oracle Retail Central Office
APPOracle14.1Oracle Retail Integration Bus
APPOracle17.0Oracle Retail Order Broker
APPOracle15.016.05.15.2Oracle Retail Point Of Service
APPOracle13.414.014.1Oracle Retail Returns Management
APPOracle14.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References
Related vulnerabilities
CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product
GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product
RCE przez deserializację PHP w Roundcube Webmail (parametr _from)
CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product
Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)
CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product
Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki