peter bassill · operator
$ cve CVE-2019-0227 JSON

CVE-2019-0227 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 91.9% (pctl 100)

Patch early

A public exploit exists.

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS91.94% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-918
On CISA KEVno
Public exploityes
Published2019-05-01
Last modified2026-06-17

Affected (37)

VendorProduct
apacheaxis
oracleagile engineering data management
oracleagile product lifecycle management
oracleapplication testing suite
oraclebig data discovery
oraclecommunications asap cartridges
oraclecommunications design studio
oraclecommunications element manager
oraclecommunications network integrity
oraclecommunications order and service management
oraclecommunications session report manager
oraclecommunications session route manager
oracleendeca information discovery studio
oracleenterprise manager base platform
oracleenterprise manager for fusion middleware
oraclefinancial services analytical applications infrastructure
oraclefinancial services compliance regulatory reporting
oraclefinancial services funds transfer pricing
oracleflexcube core banking
oracleflexcube private banking
oraclehospitality guest access
oracleinstantis enterprisetrack
oracleinternet directory
oracleknowledge
oraclepeoplesoft enterprise human capital management human resources
oraclepeoplesoft enterprise peopletools
oraclepolicy automation connector for siebel
oracleprimavera gateway
oracleprimavera unifier
oraclerapid planning
oraclereal-time decision server
oracleretail order broker
oracleretail xstore point of service
oraclesecure global desktop
oraclesiebel ui framework
oracletuxedo
oraclewebcenter portal

Public exploits

SourceTitleDate
exploit-dbApache Axis 1.4 - Remote Code Execution2019-04-09

References

→ the Explorer  ·  watch your stack  ·  NVD