PT-2019-3928 · Apache+1 · Apache Axis2+2

Published

2019-01-15

·

Updated

2024-06-21

·

CVE-2019-0227

CVSS v2.0

7.9

High

VectorAV:A/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Axis version 1.4
Description The issue is related to insufficient validation of incoming requests, which can allow a remote attacker to perform a Server Side Request Forgery (SSRF) attack. The vulnerability affects the Apache Axis 1.4 distribution, which was last released in 2006.
Recommendations For Apache Axis version 1.4, legacy users are encouraged to build from source to address the issue. As a temporary workaround, consider restricting access to vulnerable API endpoints until a patch is available. Note that the successor to Axis 1.x, Axis2, with its latest version 1.7.9, is not vulnerable to this issue. At the moment, there is no information about a newer version of Apache Axis 1.4 that contains a fix for this vulnerability.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04406
CVE-2019-0227
GHSA-H9GJ-RQRW-X4FQ

Affected Products

Apache Axis
Apache Axis2
Debian