TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-0227

HIGH
7.5

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Details CVE

Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueADJACENT_NETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie5/1/2019
Derniere modification5/8/2025
Sourcenvd
Observations honeypot0

Produits affectes

apache:axisoracle:agile_engineering_data_managementoracle:agile_product_lifecycle_managementoracle:application_testing_suiteoracle:big_data_discoveryoracle:communications_asap_cartridgesoracle:communications_design_studiooracle:communications_element_manageroracle:communications_network_integrityoracle:communications_order_and_service_managementoracle:communications_session_report_manageroracle:communications_session_route_manageroracle:endeca_information_discovery_studiooracle:enterprise_manager_base_platformoracle:enterprise_manager_for_fusion_middlewareoracle:financial_services_analytical_applications_infrastructureoracle:financial_services_compliance_regulatory_reportingoracle:financial_services_funds_transfer_pricingoracle:flexcube_core_bankingoracle:flexcube_private_bankingoracle:hospitality_guest_accessoracle:instantis_enterprisetrackoracle:internet_directoryoracle:knowledgeoracle:peoplesoft_enterprise_human_capital_management_human_resourcesoracle:peoplesoft_enterprise_peopletoolsoracle:policy_automation_connector_for_siebeloracle:primavera_gatewayoracle:primavera_unifieroracle:rapid_planningoracle:real-time_decision_serveroracle:retail_order_brokeroracle:retail_xstore_point_of_serviceoracle:secure_global_desktoporacle:siebel_ui_frameworkoracle:tuxedooracle:webcenter_portal

Faiblesses (CWE)

CWE-918

References

https://security.netapp.com/advisory/ntap-20240621-0006/(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuApr2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuapr2020.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuapr2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2020.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2021.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujul2020.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujul2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuoct2021.html(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.