PT-2024-14125 · Apache+2 · Apache Axis+2

Bing

+1

·

Published

2024-01-06

·

Updated

2024-08-02

·

CVE-2023-51441

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Axis versions through 1.3
Description The issue is related to an Improper Input Validation vulnerability in Apache Axis, which allows users with access to the admin service to perform possible Server-Side Request Forgery (SSRF). This could potentially lead to unauthorized access to internal resources. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations As a temporary workaround, consider migrating to a different SOAP engine, such as Apache Axis 2/Java. Alternatively, use a build of Axis with the patch from https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06 applied. Note that the Apache Axis project does not expect to create an Axis 1.x release fixing this problem.

Fix

RCE

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-51441
GHSA-HR2C-P8RH-238H
OPENSUSE-SU-2024:13659-1
OPENSUSE-SU-2024_0852-1
SUSE-SU-2024:0851-1
SUSE-SU-2024:0852-1
SUSE-SU-2024_0851-1
SUSE-SU-2024_0852-1

Affected Products

Apache Axis
Debian
Suse