Disclosure summary
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Source-reported weakness categories
CWE-20, CWE-918
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2020-11987
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| apache | batik | * {"versionEndIncluding":"1.13"} |
| fedoraproject | fedora | 33 |
| fedoraproject | fedora | 34 |
| oracle | agile_engineering_data_management | 6.2.1.0 |
| oracle | banking_apis | 18.3 |
| oracle | banking_apis | 19.1 |
| oracle | banking_apis | 19.2 |
| oracle | banking_apis | 20.1 |
| oracle | banking_apis | 21.1 |
| oracle | banking_digital_experience | 18.3 |
| oracle | banking_digital_experience | 19.1 |
| oracle | banking_digital_experience | 19.2 |
| oracle | banking_digital_experience | 20.1 |
| oracle | banking_digital_experience | 21.1 |
| oracle | communications_application_session_controller | 3.9m0p3 |
| oracle | communications_metasolv_solution | 6.3.0 |
| oracle | communications_metasolv_solution | 6.3.1 |
| oracle | communications_offline_mediation_controller | 12.0.0.3.0 |
| oracle | enterprise_repository | 11.1.1.7.0 |
| oracle | flexcube_universal_banking | * {"versionStartIncluding":"14.1.0","versionEndIncluding":"14.4.0"} |
| oracle | fusion_middleware_mapviewer | 12.2.1.4.0 |
| oracle | instantis_enterprisetrack | 17.1 |
| oracle | instantis_enterprisetrack | 17.2 |
| oracle | instantis_enterprisetrack | 17.3 |
| oracle | insurance_policy_administration | * {"versionStartIncluding":"11.0","versionEndIncluding":"11.3.1"} |
| oracle | product_lifecycle_analytics | 3.6.1 |
| oracle | retail_back_office | 14.1 |
| oracle | retail_central_office | 14.1 |
| oracle | retail_order_broker | 15.0 |
| oracle | retail_order_broker | 16.0 |
| oracle | retail_order_management_system_cloud_service | 19.5 |
| oracle | retail_point-of-service | 14.1 |
| oracle | retail_returns_management | 14.1 |
| oracle | weblogic_server | 12.2.1.3.0 |
| oracle | weblogic_server | 12.2.1.4.0 |
| oracle | weblogic_server | 14.1.1.0.0 |
| debian | debian_linux | 10.0 |
Original records & references
- NIST NVD record
- CVE Program record
- lists.apache.org — Mailing List, Vendor Advisory
- lists.apache.org — Mailing List, Vendor Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- xmlgraphics.apache.org — Release Notes, Vendor Advisory
- lists.apache.org — Mailing List, Vendor Advisory
- lists.apache.org — Mailing List, Vendor Advisory
- lists.debian.org — Mailing List, Third Party Advisory
- lists.debian.org
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- lists.fedoraproject.org — Mailing List, Third Party Advisory
- security.gentoo.org — Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- www.oracle.com — Patch, Third Party Advisory
- xmlgraphics.apache.org — Release Notes, Vendor Advisory
PUBLISHED 2021-02-24T13:15:11-05:00
MODIFIED 2026-10-08T18:16:55-04:00
INGESTED 2026-10-10T20:50:20-04:00