CVE-2007-2353
published 2007-04-30CVE-2007-2353: Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EXPLOIT
EPSS
27.65%
97.9th percentile
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | axis | — | — |
| debian | axis | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
osv·2022-05-01
CVE-2007-2353 [MEDIUM] Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
GHSA
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
ghsa·2022-05-01
CVE-2007-2353 [MEDIUM] CWE-200 Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
OSV
CVE-2007-2353: Apache Axis 1
osv·2007-04-30·CVSS 5.0
CVE-2007-2353 [MEDIUM] CVE-2007-2353: Apache Axis 1
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
Debian
CVE-2007-2353: axis - Apache Axis 1.0 allows remote attackers to obtain sensitive information by reque...
vendor_debian·2007·CVSS 5.0
CVE-2007-2353 [MEDIUM] CVE-2007-2353: axis - Apache Axis 1.0 allows remote attackers to obtain sensitive information by reque...
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Red Hat
CVE-2007-2353: Apache Axis 1
vendor_redhat·CVSS 5.0
CVE-2007-2353 [MEDIUM] CVE-2007-2353: Apache Axis 1
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
Statement: Red Hat ship Axis in a number of products; however the installation path of Axis is fixed and deterministic, so this flaw does not disclose otherwise unknown information. We do not plan on issuing updates to fix this issue.
No detection rules found.
No writeups or analysis indexed.
http://attrition.org/pipermail/vim/2007-April/001562.htmlhttp://www.osvdb.org/34154http://www.securityfocus.com/bid/23687https://exchange.xforce.ibmcloud.com/vulnerabilities/34167http://attrition.org/pipermail/vim/2007-April/001562.htmlhttp://www.osvdb.org/34154http://www.securityfocus.com/bid/23687https://exchange.xforce.ibmcloud.com/vulnerabilities/34167
2007-04-30
Published