Skip to main content

Vendor/product archive

apache / axis CVEs

Beta · best-effort

7 CVEs tagged to apache / axis1 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-51441

Published Jan 6, 2024

** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects A…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40743

Published Sep 5, 2023

** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-3596

Published Aug 27, 2014

The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2353

Published Apr 30, 2007

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception mess…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1