Get real-time updates on Telegram
CVE-2020-11987: batik through 1.13 (inclusive); +22 more affected products
CVE-2020-11987. CVSS 3.1 base score 8.2 (HIGH, NVD). EPSS 0.1328 (percentile 0.963), scored 2026-10-08.
Affected technology
batik · through 1.13 (inclusive)
apache
fedora · 33
fedoraproject
fedora · 34
fedoraproject
agile engineering data management · 6.2.1.0
oracle
banking apis · 18.3
oracle
banking apis · 19.1
oracle
banking apis · 19.2
oracle
banking apis · 20.1
oracle
banking apis · 21.1
oracle
banking digital experience · 18.3
oracle
banking digital experience · 19.1
oracle
banking digital experience · 19.2
oracle
banking digital experience · 20.1
oracle
banking digital experience · 21.1
oracle
communications application session controller · 3.9m0p3
oracle
communications metasolv solution · 6.3.0
oracle
communications metasolv solution · 6.3.1
oracle
communications offline mediation controller · 12.0.0.3.0
oracle
enterprise repository · 11.1.1.7.0
oracle
flexcube universal banking · from 14.1.0 (inclusive), through 14.4.0 (inclusive)
oracle
fusion middleware mapviewer · 12.2.1.4.0
oracle
instantis enterprisetrack · 17.1
oracle
instantis enterprisetrack · 17.2
oracle
instantis enterprisetrack · 17.3
oracle
insurance policy administration · from 11.0 (inclusive), through 11.3.1 (inclusive)
oracle
product lifecycle analytics · 3.6.1
oracle
retail back office · 14.1
oracle
retail central office · 14.1
oracle
retail order broker · 15.0
oracle
retail order broker · 16.0
oracle
retail order management system cloud service · 19.5
oracle
retail point-of-service · 14.1
oracle
retail returns management · 14.1
oracle
weblogic server · 12.2.1.3.0
oracle
weblogic server · 12.2.1.4.0
oracle
weblogic server · 14.1.1.0.0
oracle
debian linux · 10.0
debian
Apache Batik · Apache Batik 1.13
Vendor not specified by the source
Description’s affected range: 1.13
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. NVD’s CVSS 3.1 assessment (base score 8.2/10) rates confidentiality impact as high; integrity impact as low; availability impact as none.
- CWE
- CWE-20, CWE-918
- CCR priority
- 36.1 /100 (P4)
- CVSS 3.1
- 8.2 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N · NVD
- EPSS
- 0.1328 · percentile 0.963 · 2026-10-08
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2020-11987.html