cbcvebase.
CVE-2019-0227
published 2019-05-01

CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits…

high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EXPLOIT
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Affected

79 ranges· showing 25
VendorProductVersion rangeFixed in
apacheapache_axis_1.4
apacheaxis
debianaxis
oracleagile_engineering_data_management
oracleagile_product_lifecycle_management
oracleapplication_testing_suite
oracleapplication_testing_suite
oraclebig_data_discovery
oraclecommunications_asap_cartridges
oraclecommunications_asap_cartridges
oraclecommunications_design_studio
oraclecommunications_design_studio
oraclecommunications_design_studio
oraclecommunications_design_studio
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_network_integrity
oraclecommunications_network_integrity
oraclecommunications_order_and_service_management
oraclecommunications_order_and_service_management
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager
oraclecommunications_session_report_manager

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.5HIGH