batik: XML external entity processing vulnerability
Published Apr 18, 2017
7.5
HIGHCVSS 3.0
EPSS 4.12%
Description
In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.
Affected products
-
- Version before 1.9StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Batik | n/a |
|
No data.
Red Hat JBoss A-MQ 6.3
switchyard
Fixed · RHSA-2018:0319
Red Hat JBoss BPMS 6.4
batik
Fixed · RHSA-2017:2546
Red Hat JBoss BRMS 6.4
batik
Fixed · RHSA-2017:2547
Red Hat JBoss Fuse 6.3
switchyard
Fixed · RHSA-2018:0319
Red Hat Enterprise Linux 6
batik
Will not fix
Red Hat Enterprise Linux 7
batik
Will not fix
Red Hat JBoss Fuse Service Works 6
batik
Will not fix
Red Hat Software Collections
rh-java-common-batik
Will not fix
Red Hat Virtualization 4
batik
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss A-MQ 6.3 | switchyard | Fixed | RHSA-2018:0319 |
| Red Hat JBoss BPMS 6.4 | batik | Fixed | RHSA-2017:2546 |
| Red Hat JBoss BRMS 6.4 | batik | Fixed | RHSA-2017:2547 |
| Red Hat JBoss Fuse 6.3 | switchyard | Fixed | RHSA-2018:0319 |
| Red Hat Enterprise Linux 6 | batik | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | batik | Will not fix | n/a |
| Red Hat JBoss Fuse Service Works 6 | batik | Will not fix | n/a |
| Red Hat Software Collections | rh-java-common-batik | Will not fix | n/a |
| Red Hat Virtualization 4 | batik | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The batik package is no longer used or required by the Red Hat Virtualization Manager. Red Hat recommends removing it after updating to Red Hat Virtualization 4.1.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
AV:N/AC:M/Au:S/C:C/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.12% (0.04118) | 90.47th | v5 (v2026.06.15) |
| Sep 22, 2026 | 4.12% (0.04118) | 90.34th | v5 (v2026.06.15) |
| Sep 21, 2026 | 5.37% (0.05371) | 92.34th | v5 (v2026.06.15) |
| Sep 6, 2026 | 4.12% (0.04118) | 90.11th | v5 (v2026.06.15) |
| Sep 5, 2026 | 5.37% (0.05371) | 92.18th | v5 (v2026.06.15) |
| Aug 30, 2026 | 4.12% (0.04118) | 90.06th | v5 (v2026.06.15) |
| Aug 28, 2026 | 5.37% (0.05371) | 92.13th | v5 (v2026.06.15) |
| Aug 24, 2026 | 4.12% (0.04118) | 90.00th | v5 (v2026.06.15) |
| Aug 23, 2026 | 5.37% (0.05371) | 92.10th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.12% (0.04118) | 89.45th | v5 (v2026.06.15) |
| May 30, 2026 | 1.43% (0.01431) | 80.97th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.22% (0.00220) | 42.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.17% (0.00170) | 55.37th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.17% (0.00170) | 53.10th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00200) | 56.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.54% (0.02537) | 81.93th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.54% (0.02537) | 80.16th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.54% (0.02537) | 58.67th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.70% (0.08695) | 85.95th | v1 |
| Jan 6, 2022 | 8.70% (0.08695) | 85.79th | v1 |
| Sep 1, 2021 | 8.70% (0.08695) | 93.13th | v1 |
| Apr 14, 2021 | 8.70% (0.08695) | 0.00th | v1 |
References (16)
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html x_refsource_CONFIRM
- http://www.securityfocus.com/bid/97948 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038334 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/errata/RHSA-2017:2546 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2017:2547 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2018:0319 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2017-5662 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1443592 Issue Tracking
- https://github.com/advisories/GHSA-qwgx-59jw-qfg9 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-5662
- https://www.cve.org/CVERecord?id=CVE-2017-5662
- https://www.debian.org/security/2018/dsa-4215 vendor-advisoryx_refsource_DEBIAN
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISC
- https://xmlgraphics.apache.org/security.html x_refsource_CONFIRMPatchVendor Advisory
Change history (0)
No recorded changes yet.