Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2019-0227

Severity
7.5HIGH
EPSS
89.8%
top 0.43%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 1
Latest updateJul 15

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages40 packages

NVDapache/axis1.4
CVEListV5apache/apache_axis_1.4Apache Axis 1.4
Mavenaxis:axis1.4

Patches

🔴Vulnerability Details

4
OSV
Server Side Request Forgery in Apache Axis2019-05-14
GHSA
Server Side Request Forgery in Apache Axis2019-05-14
CVEList
CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 12019-05-01
OSV
CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 12019-05-01

💥Exploits & PoCs

1
Exploit-DB
Apache Axis 1.4 - Remote Code Execution2019-04-09

📋Vendor Advisories

11
Oracle
Oracle Oracle Analytics Risk Matrix: Installation (Apache Axis) — CVE-2019-02272023-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: BI Publisher Security (Apache Axis) — CVE-2019-02272022-07-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Oracle Directory Services Mngr (Apache Axis) — CVE-2019-02272022-04-15
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Bills And Collections (Apache Axis) — CVE-2019-02272021-10-15
Oracle
Oracle Oracle Siebel CRM Risk Matrix: SWSE Server (Apache Axis) — CVE-2019-02272021-04-15

💬Community

2
Bugzilla
CVE-2019-0227 axis2: axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution. [fedora-all]2019-04-18
Bugzilla
CVE-2019-0227 axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.2019-04-11