Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-0250

Опубликовано: 25 июл. 2012
Источник: redhat
CVSS2: 5.8
EPSS Низкий

Описание

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

It was found that batik was vulnerable to XML External Entity attacks when parsing SVG files. A remote attacker able to send malicious SVG content to the affected server could use this flaw to read files accessible to the user running the application server, and potentially perform other more advanced XXE attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Toolset 2.1batikWill not fix
Red Hat Enterprise Linux 6batikWill not fix
Red Hat Enterprise Linux 7batikWill not fix
Red Hat Enterprise Virtualization 3jasperreports-server-proWill not fix
Red Hat JBoss BRMS 5batikWill not fix
Red Hat JBoss Enterprise Web Server 1fuseNot affected
Red Hat JBoss Fuse Service Works 6batikAffected
Red Hat JBoss SOA Platform 5batikWill not fix
Red Hat OpenShift Enterprise 2jboss-eap6-modulesNot affected
Red Hat OpenShift Enterprise 2openshift-origin-cartridge-fuseNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-611
https://bugzilla.redhat.com/show_bug.cgi?id=1203762batik: XML External Entity (XXE) injection in SVG parsing

EPSS

Процентиль: 78%
0.01083
Низкий

5.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

nvd
почти 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file.

debian
почти 11 лет назад

XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) ...

github
больше 3 лет назад

Improper Input Validation in Apache Batik

EPSS

Процентиль: 78%
0.01083
Низкий

5.8 Medium

CVSS2