PT-2010-2020 · Apache · Apache Axis2
Joshua Abraham
+1
·
Published
2010-10-18
·
Updated
2018-10-10
·
CVE-2010-0219
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Axis2 (affected versions not specified)
Description
The issue is related to a default password set for the admin account in Apache Axis2, which is used in various products. This default password makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Axis2