CVE-2019-0227
published 2019-05-01CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits…
PriorityP266high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EXPLOIT
EPSS
86.50%
99.7th percentile
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Affected
79 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_axis_1.4 | — | — |
| apache | axis | — | — |
| debian | axis | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_product_lifecycle_management | — | — |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | big_data_discovery | — | — |
| oracle | communications_asap_cartridges | — | — |
| oracle | communications_asap_cartridges | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_element_manager | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_order_and_service_management | — | — |
| oracle | communications_order_and_service_management | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
| oracle | communications_session_report_manager | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlhttp://localhost:{port}/axis/services/AdminService?method=%21--%3E%3Cns1%3Adeployment+xmlns%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2F%22+xmlns%3Ajava%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2Fproviders%2Fjava%22+xmlns%3Ans1%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2F%22%3E%3Cns1%3Aservice+name%3D%22exploitservice%22+provider%3D%22java%3ARPC%22%3E%3CrequestFlow%3E%3Chandler+type%3D%22RandomLog%22%2F%3E%3C%2FrequestFlow%3E%3Cns1%3Aparameter+name%3D%22className%22+value%3D%22java.util.Random%22%2F%3E%3Cns1%3Aparameter+name%3D%22allowedMethods%22+value%3D%22%2A%22%2F%3E%3C%2Fns1%3Aservice%3E%3Chandler+name%3D%22RandomLog%22+type%3D%22java%3Aorg.apache.axis.handlers.LogHandler%22+%3E%3Cparameter+name%3D%22LogHandler.fileName%22+value%3D%22↗
urlhttp://localhost:{port}/axis/services/AdminService?method=%21--%3E%3Cns1%3Aundeployment+xmlns%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2F%22+xmlns%3Ans1%3D%22http%3A%2F%2Fxml.apache.org%2Faxis%2Fwsdd%2F%22%3E%3Cns1%3Aservice+name%3D%22exploitservice%22%2F%3E%3C%2Fns1%3Aundeployment↗
- →Monitor for HTTP POST requests to /axis/services/AdminService with a 'method' query parameter containing URL-encoded WSDD deployment XML — this is the SSRF-driven service deployment step of the exploit. ↗
- →Detect HTTP POST requests to /axis/StockQuoteService.jws containing a SOAP body with a hard-coded domain name endpoint — this is the trigger for the SSRF redirect chain. ↗
- →Alert on creation or access of 'exploit.jsp' under the Axis web application root — this is the dropped JSP webshell written via the LogHandler abuse. ↗
- →Detect ARP spoofing activity (arpspoof process) combined with iptables NAT PREROUTING rules redirecting port 80 traffic — these are the MITM setup steps used to intercept the SSRF-initiated outbound HTTP request. ↗
- →Look for HTTP 301 redirects from an unexpected host on port 80 pointing to an internal Axis AdminService URL with WSDD deployment XML — this is the SSRF redirect server used to pivot the Axis server into deploying a malicious service. ↗
- →Detect SOAP requests with SOAPAction header set to an empty string or 'something' targeting Axis JWS endpoints — these are characteristic of the exploit's TriggerSSRF and CreateJsp functions. ↗
- ·The exploit requires the attacker to be on the same network segment as the target (adjacent network) to perform ARP spoofing — this is not a remotely exploitable vulnerability from the internet without LAN access. ↗
- ·Only Apache Axis 1.4 is vulnerable; Axis2 (latest 1.7.9) is not affected. Axis 1.4 has not had an official release since 2006. ↗
- ·Red Hat has marked this as 'Will not fix' for both RHEL 5 and RHEL 6 axis packages, meaning patched RPMs will not be provided. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Analytics Risk Matrix: Installation (Apache Axis) — CVE-2019-0227
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Analytics Risk Matrix: Installation (Apache Axis) — CVE-2019-0227
Oracle Oracle Analytics Risk Matrix: Installation (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security (Apache Axis) — CVE-2019-0227
vendor_oracle·2022-07-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security (Apache Axis) — CVE-2019-0227
Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Oracle Directory Services Mngr (Apache Axis) — CVE-2019-0227
vendor_oracle·2022-04-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Oracle Directory Services Mngr (Apache Axis) — CVE-2019-0227
Oracle Oracle Fusion Middleware Risk Matrix: Oracle Directory Services Mngr (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-10-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) — CVE-2019-0227
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-04-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) — CVE-2019-0227
Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) — CVE-2019-0227
vendor_oracle·2021-01-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) — CVE-2019-0227
Oracle Oracle Fusion Middleware Risk Matrix: Platform Installation (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujan2020 (JAN 2020)
Red Hat
axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
vendor_redhat·2019-04-09·CVSS 7.5
CVE-2019-0227 [HIGH] CWE-547 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Package: axis (Red Hat Enterprise Linux 5) - Will not fix
Package: axis (Red Hat Enterprise Linux 6) - Will not fix
Debian
CVE-2019-0227: axis - A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 ...
vendor_debian·2019·CVSS 7.5
CVE-2019-0227 [HIGH] CVE-2019-0227: axis - A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 ...
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
Server Side Request Forgery in Apache Axis
osv·2019-05-14
CVE-2019-0227 [HIGH] Server Side Request Forgery in Apache Axis
Server Side Request Forgery in Apache Axis
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
GHSA
Server Side Request Forgery in Apache Axis
ghsa·2019-05-14
CVE-2019-0227 [HIGH] CWE-918 Server Side Request Forgery in Apache Axis
Server Side Request Forgery in Apache Axis
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
OSV
CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1
osv·2019-05-01·CVSS 7.5
CVE-2019-0227 [HIGH] CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
No detection rules found.
Bugzilla
CVE-2019-0227 axis2: axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution. [fedora-all]
bugzilla·2019-04-18·CVSS 7.5
CVE-2019-0227 [HIGH] CVE-2019-0227 axis2: axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution. [fedora-all]
CVE-2019-0227 axis2: axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedp
Bugzilla
CVE-2019-0227 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
bugzilla·2019-04-11·CVSS 7.5
CVE-2019-0227 [HIGH] CVE-2019-0227 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
CVE-2019-0227 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.
An expired hard coded domain, used in a default example service named “StockQuoteService.jws”, could lead to remote code execution.
External References:
https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/
Discussion:
Analysis:
The server application using axis needs to be vulnerable to server side request forgery flaw (SSRF). In a Server-Side Request Forgery (SSRF) attack, the attacker can abuse functionality on the server to read or update internal resources. The attacker can supply or a modify a URL which the code running on the server will read or submit data to, and by carefully selecting the URLs, the attac
https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apache.org%3Ehttps://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3Ehttps://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/https://security.netapp.com/advisory/ntap-20240621-0006/https://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-05-01
Published