Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-2353

Severity
5.0MEDIUM
EPSS
4.3%
top 11.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedApr 30
Latest updateMay 1

Description

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

NVDapache/axis1.0

🔴Vulnerability Details

4
OSV
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor2022-05-01
GHSA
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor2022-05-01
OSV
CVE-2007-2353: Apache Axis 12007-04-30
CVEList
CVE-2007-2353: Apache Axis 12007-04-30

💥Exploits & PoCs

1
Exploit-DB
Apache AXIS 1.0 - Non-Existent WSDL Path Information Disclosure2007-04-27

📋Vendor Advisories

2
Debian
CVE-2007-2353: axis - Apache Axis 1.0 allows remote attackers to obtain sensitive information by reque...2007
Red Hat
CVE-2007-2353: Apache Axis 1
CVE-2007-2353 (MEDIUM CVSS 5) | Apache Axis 1.0 allows remote attac | cvebase.io