GHSA-2h63-qp69-fwvw · Severity: high · Ecosystem: maven — Server-side request forgery (SSRF) in Apache Batik
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Conclusion & alert: CVE-2020-11987 is rated Moderate Risk (61.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.36%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-04 | 0.57% | 1.36% | +0.78% |
| 2 | 2026-03-01 | 1.36% | 0.57% | -0.78% |
| 3 | 2026-02-04 | — | 1.36% | — |
Full EPSS history (39 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.2 | 3.1 | HIGH |
|
3.9 | 4.2 | [email protected] |
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
GHSA-2h63-qp69-fwvw · Severity: high · Ecosystem: maven — Server-side request forgery (SSRF) in Apache Batik
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-11987 not yet assigned priority: Debian including 1 source packages (batik), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-11987 |
gentoo
|
normal | CVE-2020-11987: 1 GLSA(s) (202401-11), 1 atom(s) (dev-java/batik); latest impact normal. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2020-11987 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-11987 |
suse
|
medium | CVE-2020-11987 severity moderate: SUSE including 28 source package names (xmlgraphics-batik-1.15-150200.4.4.3, xmlgraphics-batik-1.15-2.1, …), 81 product×package rows across 21 product lines (SUSE Enterprise Storage 7, SUSE Enterprise Storage 7.1, … (21 product lines)): Fixed 81. | https://www.suse.com/security/cve/CVE-2020-11987/ |
ubuntu
|
medium | CVE-2020-11987 medium priority: Ubuntu including 1 source packages (batik), 16 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 7, released 4, needs-triage 3, not-affected 2. | https://ubuntu.com/security/CVE-2020-11987 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | batik | <= 1.13 | cpe:2.3:a:apache:batik:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 33 | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.2.1.0 | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* |
| oracle | banking_apis | 18.3 | cpe:2.3:a:oracle:banking_apis:18.3:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.1 | cpe:2.3:a:oracle:banking_apis:19.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 19.2 | cpe:2.3:a:oracle:banking_apis:19.2:*:*:*:*:*:*:* |
| oracle | banking_apis | 20.1 | cpe:2.3:a:oracle:banking_apis:20.1:*:*:*:*:*:*:* |
| oracle | banking_apis | 21.1 | cpe:2.3:a:oracle:banking_apis:21.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 18.3 | cpe:2.3:a:oracle:banking_digital_experience:18.3:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.1 | cpe:2.3:a:oracle:banking_digital_experience:19.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 19.2 | cpe:2.3:a:oracle:banking_digital_experience:19.2:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 20.1 | cpe:2.3:a:oracle:banking_digital_experience:20.1:*:*:*:*:*:*:* |
| oracle | banking_digital_experience | 21.1 | cpe:2.3:a:oracle:banking_digital_experience:21.1:*:*:*:*:*:*:* |
| oracle | communications_application_session_controller | 3.9m0p3 | cpe:2.3:a:oracle:communications_application_session_controller:3.9m0p3:*:*:*:*:*:*:* |
| oracle | communications_metasolv_solution | 6.3.0 | cpe:2.3:a:oracle:communications_metasolv_solution:6.3.0:*:*:*:*:*:*:* |
| oracle | communications_metasolv_solution | 6.3.1 | cpe:2.3:a:oracle:communications_metasolv_solution:6.3.1:*:*:*:*:*:*:* |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | enterprise_repository | 11.1.1.7.0 | cpe:2.3:a:oracle:enterprise_repository:11.1.1.7.0:*:*:*:*:*:*:* |
| oracle | flexcube_universal_banking | >= 14.1.0, <= 14.4.0 | cpe:2.3:a:oracle:flexcube_universal_banking:*:*:*:*:*:*:*:* |
| oracle | fusion_middleware_mapviewer | 12.2.1.4.0 | cpe:2.3:a:oracle:fusion_middleware_mapviewer:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | instantis_enterprisetrack | 17.1 | cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* |
| oracle | instantis_enterprisetrack | 17.2 | cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:* |
| oracle | instantis_enterprisetrack | 17.3 | cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:* |
| oracle | insurance_policy_administration | >= 11.0, <= 11.3.1 | cpe:2.3:a:oracle:insurance_policy_administration:*:*:*:*:*:*:*:* |
| oracle | product_lifecycle_analytics | 3.6.1 | cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:* |
| oracle | retail_back_office | 14.1 | cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:* |
| oracle | retail_central_office | 14.1 | cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 15.0 | cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:* |
| oracle | retail_order_broker | 16.0 | cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:* |
| oracle | retail_order_management_system_cloud_service | 19.5 | cpe:2.3:a:oracle:retail_order_management_system_cloud_service:19.5:*:*:*:*:*:*:* |
| oracle | retail_point-of-service | 14.1 | cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:* |
| oracle | retail_returns_management | 14.1 | cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.3.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 12.2.1.4.0 | cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:* |
| oracle | weblogic_server | 14.1.1.0.0 | cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |