CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2020-11987: batik through 1.13 (inclusive); +22 more affected products

CVE-2020-11987. CVSS 3.1 base score 8.2 (HIGH, NVD). EPSS 0.1328 (percentile 0.963), scored 2026-10-08.

Affected technology

batik · through 1.13 (inclusive)
apache

fedora · 33
fedoraproject

fedora · 34
fedoraproject

agile engineering data management · 6.2.1.0
oracle

banking apis · 18.3
oracle

banking apis · 19.1
oracle

banking apis · 19.2
oracle

banking apis · 20.1
oracle

banking apis · 21.1
oracle

banking digital experience · 18.3
oracle

banking digital experience · 19.1
oracle

banking digital experience · 19.2
oracle

banking digital experience · 20.1
oracle

banking digital experience · 21.1
oracle

communications application session controller · 3.9m0p3
oracle

communications metasolv solution · 6.3.0
oracle

communications metasolv solution · 6.3.1
oracle

communications offline mediation controller · 12.0.0.3.0
oracle

enterprise repository · 11.1.1.7.0
oracle

flexcube universal banking · from 14.1.0 (inclusive), through 14.4.0 (inclusive)
oracle

fusion middleware mapviewer · 12.2.1.4.0
oracle

instantis enterprisetrack · 17.1
oracle

instantis enterprisetrack · 17.2
oracle

instantis enterprisetrack · 17.3
oracle

insurance policy administration · from 11.0 (inclusive), through 11.3.1 (inclusive)
oracle

product lifecycle analytics · 3.6.1
oracle

retail back office · 14.1
oracle

retail central office · 14.1
oracle

retail order broker · 15.0
oracle

retail order broker · 16.0
oracle

retail order management system cloud service · 19.5
oracle

retail point-of-service · 14.1
oracle

retail returns management · 14.1
oracle

weblogic server · 12.2.1.3.0
oracle

weblogic server · 12.2.1.4.0
oracle

weblogic server · 14.1.1.0.0
oracle

debian linux · 10.0
debian

Apache Batik · Apache Batik 1.13
Vendor not specified by the source

Description’s affected range: 1.13

Component: Not specified by the source

Attack conditions (NVD, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

An attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. NVD’s CVSS 3.1 assessment (base score 8.2/10) rates confidentiality impact as high; integrity impact as low; availability impact as none.

Published

CWE
CWE-20, CWE-918
CCR priority
36.1 /100 (P4)
CVSS 3.1
8.2 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N · NVD
EPSS
0.1328 · percentile 0.963 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2020-11987.html