CVE-2015-0250
Summary
| CVE | CVE-2015-0250 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-24 17:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | XML external entity (XXE) vulnerability in the SVG to (1) PNG and (2) JPG conversion classes in Apache Batik 1.x before 1.8 allows remote attackers to read arbitrary files or cause a denial of service via a crafted SVG file. |
Risk And Classification
Primary CVSS: v2.0 6.4 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:P/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Batik | All | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 12.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 14.10 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Support / Security / Advisories / / MDVSA-2015:203 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| The Apache™ XML Graphics Project - Community | af854a3a-2127-422b-91ae-364da2661108 | xmlgraphics.apache.org | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Full Disclosure: [CVE-2015-0250] Apache Batik Information Disclosure Vulnerability (XXE Injection) | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| Apache Batik XML External Entity Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| IBM Security Bulletin: Multiple Security Vulnerabilities fixed in IBM WebSphere Application Server 8.0.0.11 - United States | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | |
| Debian -- Security Information -- DSA-3205-1 batik | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Apache Batik XXE Injection ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| USN-2548-1: Batik vulnerability | Ubuntu | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Patch |
| Mageia Advisory: MGASA-2015-0138 - Updated batik packages fix security vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.