{
    "id": "CVE-2019-0227",
    "published": "2019-05-01 21:29:00",
    "last_modified": "2026-06-17 02:08:02",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-918",
    "description": "A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.",
    "epss_score": "0.91940",
    "epss_percentile": "0.99817",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:24:11",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "apache",
            "product": "axis"
        },
        {
            "vendor": "oracle",
            "product": "agile_engineering_data_management"
        },
        {
            "vendor": "oracle",
            "product": "agile_product_lifecycle_management"
        },
        {
            "vendor": "oracle",
            "product": "application_testing_suite"
        },
        {
            "vendor": "oracle",
            "product": "big_data_discovery"
        },
        {
            "vendor": "oracle",
            "product": "communications_asap_cartridges"
        },
        {
            "vendor": "oracle",
            "product": "communications_design_studio"
        },
        {
            "vendor": "oracle",
            "product": "communications_element_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_network_integrity"
        },
        {
            "vendor": "oracle",
            "product": "communications_order_and_service_management"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_report_manager"
        },
        {
            "vendor": "oracle",
            "product": "communications_session_route_manager"
        },
        {
            "vendor": "oracle",
            "product": "endeca_information_discovery_studio"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_base_platform"
        },
        {
            "vendor": "oracle",
            "product": "enterprise_manager_for_fusion_middleware"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_analytical_applications_infrastructure"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_compliance_regulatory_reporting"
        },
        {
            "vendor": "oracle",
            "product": "financial_services_funds_transfer_pricing"
        },
        {
            "vendor": "oracle",
            "product": "flexcube_core_banking"
        },
        {
            "vendor": "oracle",
            "product": "flexcube_private_banking"
        },
        {
            "vendor": "oracle",
            "product": "hospitality_guest_access"
        },
        {
            "vendor": "oracle",
            "product": "instantis_enterprisetrack"
        },
        {
            "vendor": "oracle",
            "product": "internet_directory"
        },
        {
            "vendor": "oracle",
            "product": "knowledge"
        },
        {
            "vendor": "oracle",
            "product": "peoplesoft_enterprise_human_capital_management_human_resources"
        },
        {
            "vendor": "oracle",
            "product": "peoplesoft_enterprise_peopletools"
        },
        {
            "vendor": "oracle",
            "product": "policy_automation_connector_for_siebel"
        },
        {
            "vendor": "oracle",
            "product": "primavera_gateway"
        },
        {
            "vendor": "oracle",
            "product": "primavera_unifier"
        },
        {
            "vendor": "oracle",
            "product": "rapid_planning"
        },
        {
            "vendor": "oracle",
            "product": "real-time_decision_server"
        },
        {
            "vendor": "oracle",
            "product": "retail_order_broker"
        },
        {
            "vendor": "oracle",
            "product": "retail_xstore_point_of_service"
        },
        {
            "vendor": "oracle",
            "product": "secure_global_desktop"
        },
        {
            "vendor": "oracle",
            "product": "siebel_ui_framework"
        },
        {
            "vendor": "oracle",
            "product": "tuxedo"
        },
        {
            "vendor": "oracle",
            "product": "webcenter_portal"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "46682",
            "title": "Apache Axis 1.4 - Remote Code Execution",
            "date": "2019-04-09",
            "url": "https://www.exploit-db.com/exploits/46682"
        }
    ],
    "refs_list": [
        "https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apache.org%3E",
        "https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E",
        "https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/",
        "https://security.netapp.com/advisory/ntap-20240621-0006/",
        "https://www.oracle.com/security-alerts/cpuApr2021.html",
        "https://www.oracle.com/security-alerts/cpuapr2020.html",
        "https://www.oracle.com/security-alerts/cpuapr2022.html",
        "https://www.oracle.com/security-alerts/cpujan2020.html",
        "https://www.oracle.com/security-alerts/cpujan2021.html",
        "https://www.oracle.com/security-alerts/cpujul2020.html",
        "https://www.oracle.com/security-alerts/cpujul2022.html",
        "https://www.oracle.com/security-alerts/cpuoct2021.html",
        "https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html",
        "https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apache.org%3E",
        "https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E",
        "https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/",
        "https://security.netapp.com/advisory/ntap-20240621-0006/",
        "https://www.oracle.com/security-alerts/cpuApr2021.html",
        "https://www.oracle.com/security-alerts/cpuapr2020.html",
        "https://www.oracle.com/security-alerts/cpuapr2022.html",
        "https://www.oracle.com/security-alerts/cpujan2020.html",
        "https://www.oracle.com/security-alerts/cpujan2021.html",
        "https://www.oracle.com/security-alerts/cpujul2020.html",
        "https://www.oracle.com/security-alerts/cpujul2022.html",
        "https://www.oracle.com/security-alerts/cpuoct2021.html"
    ]
}