CVE-2023-40743
published 2023-09-05CVE-2023-40743: ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through…
PriorityP352critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.93%
77.7th percentile
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE. As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | axis | < 2023-08-01 | 2023-08-01 |
| apache | axis | >= 0 < 1.4-28+deb11u1 | 1.4-28+deb11u1 |
| apache | axis | >= 0 < 1.4-28+deb12u1 | 1.4-28+deb12u1 |
| apache | axis | >= 0 < 1.4-29 | 1.4-29 |
| apache | axis | >= 0 < 1.4-29 | 1.4-29 |
| apache | axis | >= 0 < 1.4-28+deb10u1build0.20.04.1 | 1.4-28+deb10u1build0.20.04.1 |
| apache | axis | >= 0 < 1.4-28+deb10u1build0.22.04.1 | 1.4-28+deb10u1build0.22.04.1 |
| apache | axis | >= 0 < 1.4-24ubuntu0.1~esm1 | 1.4-24ubuntu0.1~esm1 |
| apache | axis | >= 0 < 1.4-25ubuntu0.1~esm1 | 1.4-25ubuntu0.1~esm1 |
| apache_software_foundation | apache_axis | <= 1.3 | — |
| debian | axis | < axis 1.4-28+deb12u1 (bookworm) | axis 1.4-28+deb12u1 (bookworm) |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
axis vulnerability
osv·2023-11-02·CVSS 9.8
CVE-2023-40743 [CRITICAL] axis vulnerability
axis vulnerability
It was discovered that Axis incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file,
a remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2023-40743)
GHSA
Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
ghsa·2023-09-05
CVE-2023-40743 [CRITICAL] CWE-20 Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE.
As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does n
OSV
CVE-2023-40743: ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1
osv·2023-09-05·CVSS 9.8
CVE-2023-40743 [CRITICAL] CVE-2023-40743: ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE. As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this
OSV
Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
osv·2023-09-05
CVE-2023-40743 [CRITICAL] Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE.
As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does n
Ubuntu
Axis vulnerability
vendor_ubuntu·2023-11-02·CVSS 9.8
CVE-2023-40743 [CRITICAL] Axis vulnerability
Title: Axis vulnerability
Summary: Axis could be made to crash or execute arbitrary code if it received specially
crafted input.
It was discovered that Axis incorrectly handled certain inputs. If a user or
an automated system were tricked into opening a specially crafted input file,
a remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2023-40743)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-40743: axis - ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an applicati...
vendor_debian·2023·CVSS 9.8
CVE-2023-40743 [CRITICAL] CVE-2023-40743: axis - ** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an applicati...
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allows potentially dangerous lookup mechanisms such as LDAP. When passing untrusted input to this API method, this could expose the application to DoS, SSRF and even attacks leading to RCE. As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. As a workaround, you may review your code to verify no untrusted or unsanitized input is passed to "ServiceFactory.getService", or by applying the patch from https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210 . The Apache Axis project does not expect to create an Axis 1.x release fixing this
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210https://lists.apache.org/thread/gs0qgk2mgss7zfhzdd6ftfjvm4kp7v82https://lists.debian.org/debian-lts-announce/2023/10/msg00025.htmlhttps://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210https://lists.apache.org/thread/gs0qgk2mgss7zfhzdd6ftfjvm4kp7v82https://lists.debian.org/debian-lts-announce/2023/10/msg00025.html
2023-09-05
Published