CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Apache. Its EPSS score suggests a 19.3% probability of exploitation in the next 30 days.
CVE
CVE-2018-8013
Severity
CRITICAL
CVSS
9.8
EPSS
19.29%
Apache
Original NVD Description
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
Related CVEs
Other vulnerabilities affecting the same vendor(s)