6.4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:N/A:P
8.9 High
AI Score
Confidence
High
0.043 Low
EPSS
Percentile
92.3%
Nicolas Gregoire and Kevin Schaller discovered that Batik would load XML
external entities by default. If a user or automated system were tricked
into opening a specially crafted SVG file, an attacker could possibly
obtain access to arbitrary files or cause resource consumption.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 14.10 | noarch | libbatik-java | <ย 1.7.ubuntu-8ubuntu2.14.10.1 | UNKNOWN |
Ubuntu | 14.04 | noarch | libbatik-java | <ย 1.7.ubuntu-8ubuntu2.14.04.1 | UNKNOWN |
Ubuntu | 12.04 | noarch | libbatik-java | <ย 1.7.ubuntu-8ubuntu1.1 | UNKNOWN |