In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Apache
Subscribe
|
Batik
Subscribe
|
|
Canonical
Subscribe
|
Ubuntu Linux
Subscribe
|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Oracle
Subscribe
|
Business Intelligence
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Metasolv Solution
Subscribe
Communications Webrtc Session Controller
Subscribe
Data Integrator
Subscribe
Enterprise Repository
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Fusion Middleware Mapviewer
Subscribe
Instantis Enterprisetrack
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Policy Administration J2ee
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Integration Bus
Subscribe
Retail Order Broker
Subscribe
Retail Point-of-service
Subscribe
Retail Returns Management
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1385-1 | batik security update |
Debian DSA |
DSA-4215-1 | batik security update |
Github GHSA |
GHSA-25gw-4pcc-45cf | Deserialization of Untrusted Data in Apache Batik |
Ubuntu USN |
USN-3661-1 | Batik vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T23:16:36.073Z
Reserved: 2018-03-09T00:00:00
Link: CVE-2018-8013
No data.
Status : Modified
Published: 2018-05-24T16:29:00.380
Modified: 2024-11-21T04:13:05.577
Link: CVE-2018-8013
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN