CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2018-8013

CVSS 9.8v3.0pub. 2018-05-24upd. 2024-11-21

In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Apache Batik

    APP
    Apache
    1.0 – 1.10 (excl.)
  • Canonical Ubuntu

    OS
    Canonical
    14.04
  • Debian

    OS
    Debian
    7.08.09.0
  • Oracle Business Intelligence

    APP
    Oracle
    11.1.1.7.011.1.1.9.012.2.1.3.012.2.1.4.0
  • Oracle Communications Diameter Signaling Router

    APP
    Oracle
    < 8.3
  • Oracle Communications Metasolv Solution

    APP
    Oracle
    6.3.0
  • Oracle Communications Webrtc Session Controller

    APP
    Oracle
    < 7.2
  • Oracle Data Integrator

    APP
    Oracle
    12.2.1.3.0
  • Oracle Enterprise Repository

    APP
    Oracle
    11.1.1.7.012.1.3.0.0
  • Oracle Financial Services Analytical Applications Infrastructure

    APP
    Oracle
    7.3.3.0.0 – 7.3.3.0.28.0.0.0.0 – 8.0.7.1.0
  • Oracle Fusion Middleware Mapviewer

    APP
    Oracle
    12.2.1.212.2.1.3
  • Oracle Instantis Enterprisetrack

    APP
    Oracle
    17.117.217.3
  • Oracle Insurance Calculation Engine

    APP
    Oracle
    10.1.110.2.1
  • Oracle Insurance Policy Administration J2ee

    APP
    Oracle
    10.010.2
  • Oracle Jd Edwards Enterpriseone Tools

    APP
    Oracle
    9.2
  • Oracle Retail Back Office

    APP
    Oracle
    13.313.41414.1
  • Oracle Retail Central Office

    APP
    Oracle
    14.1
  • Oracle Retail Integration Bus

    APP
    Oracle
    17.0
  • Oracle Retail Order Broker

    APP
    Oracle
    15.016.05.15.2
  • Oracle Retail Point Of Service

    APP
    Oracle
    13.414.014.1
  • Oracle Retail Returns Management

    APP
    Oracle
    14.1
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki