Lucene search

K
cve[email protected]CVE-2022-41704
HistoryOct 25, 2022 - 5:15 p.m.

CVE-2022-41704

2022-10-2517:15:57
CWE-918
web.nvd.nist.gov
101
6
cve-2022-41704
vulnerability
batik
apache xml graphics
untrusted java code
svg
nvd
security update

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.5%

A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16.

Affected configurations

Vulners
NVD
Node
apachexml_graphics_batikRange1.15
CPENameOperatorVersion
apache:batikapache batiklt1.16

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "Apache XML Graphics",
    "versions": [
      {
        "version": "Batik",
        "status": "affected",
        "lessThanOrEqual": "1.15",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

7.4 High

AI Score

Confidence

High

0.011 Low

EPSS

Percentile

84.5%