{
  "threat_severity" : "Moderate",
  "public_date" : "2017-04-10T00:00:00Z",
  "bugzilla" : {
    "description" : "batik: XML external entity processing vulnerability",
    "id" : "1443592",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1443592"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-611",
  "details" : [ "In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server - including confidential or sensitive files - would be possible. XXE can also be used to attack the availability of the server via denial of service as the references within a xml document can trivially trigger an amplification attack.", "An XXE vulnerability was found in Apache Batik which could allow a remote attacker to retrieve the files on the vulnerable server's filesystem by uploading specially crafted SVG images. The vulnerability could also allow a denial of service condition by performing an amplification attack." ],
  "statement" : "The batik package is no longer used or required by the Red Hat Virtualization Manager. Red Hat recommends removing it after updating to Red Hat Virtualization 4.1.",
  "affected_release" : [ {
    "product_name" : "Red Hat JBoss A-MQ 6.3",
    "release_date" : "2018-02-14T00:00:00Z",
    "advisory" : "RHSA-2018:0319",
    "cpe" : "cpe:/a:redhat:jboss_amq:6.3",
    "package" : "switchyard"
  }, {
    "product_name" : "Red Hat JBoss BPMS 6.4",
    "release_date" : "2017-08-29T00:00:00Z",
    "advisory" : "RHSA-2017:2546",
    "cpe" : "cpe:/a:redhat:jboss_bpms:6.4",
    "package" : "batik"
  }, {
    "product_name" : "Red Hat JBoss BRMS 6.4",
    "release_date" : "2017-08-29T00:00:00Z",
    "advisory" : "RHSA-2017:2547",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:6.4",
    "package" : "batik"
  }, {
    "product_name" : "Red Hat JBoss Fuse 6.3",
    "release_date" : "2018-02-14T00:00:00Z",
    "advisory" : "RHSA-2018:0319",
    "cpe" : "cpe:/a:redhat:jboss_fuse:6.3",
    "package" : "switchyard"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Will not fix",
    "package_name" : "batik",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Will not fix",
    "package_name" : "batik",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat JBoss Fuse Service Works 6",
    "fix_state" : "Will not fix",
    "package_name" : "batik",
    "cpe" : "cpe:/a:redhat:jboss_fuse_service_works:6"
  }, {
    "product_name" : "Red Hat Software Collections",
    "fix_state" : "Will not fix",
    "package_name" : "rh-java-common-batik",
    "cpe" : "cpe:/a:redhat:rhel_software_collections:2"
  }, {
    "product_name" : "Red Hat Virtualization 4",
    "fix_state" : "Affected",
    "package_name" : "batik",
    "cpe" : "cpe:/o:redhat:rhev_hypervisor:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2017-5662\nhttps://nvd.nist.gov/vuln/detail/CVE-2017-5662" ],
  "name" : "CVE-2017-5662",
  "csaw" : false
}