CVE-2019-0227

CVE-2019-0227: vulnerability in Apache Axis 1.4

Published · Updated

45Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 92%
from disclosure to weapon0 days
Published on NVDMay 1
1st PoCApr 9
exploitation probability
92%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (5 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
no_fix_planned: Will not fix
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Affected products
Apache · Apache Axis 1.4
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.