← Vulnerability feed

Vulnerability record · CVE-2019-17566 · published 12 November 2020

CVE-2019-17566: Apache batik server-side request forgery (ssrf) vulnerability

Apache · Batik

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

7.5 CVSS 3.1 High EPSS 11% · top 4.3% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.0
11%EPSS exploitation probability, 30 days
NoNot in CISA KEV
18Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apac
https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apac
https://security.gentoo.org/glsa/202401-11
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://xmlgraphics.apache.org/security.html Vendor Advisory
https://lists.apache.org/thread.html/rab94fe68b180d2e2fba97abf6fe1ec83cff826be25f86cd90f047171%40%3Ccommits.myfaces.apac
https://lists.apache.org/thread.html/rcab14a9ec91aa4c151e0729966282920423eff50a22759fd21db6509%40%3Ccommits.myfaces.apac
https://security.gentoo.org/glsa/202401-11
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://xmlgraphics.apache.org/security.html Vendor Advisory

Track CVE-2019-17566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-17530Apache Struts forced OGNL evaluation enables remote code executionApache Struts 2.0.0 through 2.5.25 performs forced OGNL evaluation on raw user input placed in tag attributes, allowing expression language injection…KEVEPSS 96%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed7.5CVE-2020-14864Oracle Business Intelligence Enterprise Edition path traversal allows unauthenticated data accessOracle Business Intelligence Enterprise Edition contains a path traversal flaw in its Installation component affecting versions 5.5.0.0.0, 12.2.1.3.0…KEVEPSS 97%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2015-0235glibc gethostbyname heap buffer overflow (GHOST)CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reach…EPSS 95%analysed9.8CVE-2022-23852Libexpat project libexpat integer overflow vulnerabilityExpat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.EPSS 4.6%9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2021-2456Oracle Business Intelligence Enterprise Edition unauthenticated takeoverOracle Business Intelligence Enterprise Edition 12.2.1.4.0 contains a flaw in the Analytics Web General component that is reachable over HTTP without…EPSS 81%analysed

Source: NIST National Vulnerability Database (record CVE-2019-17566), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.