Skip to main content

Vendor/product archive

apache / axis2 CVEs

Beta · best-effort

6 CVEs tagged to apache / axis21 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2012-5785

Published Nov 4, 2012

Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certifica…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5351

Published Oct 9, 2012

Apache Axis2 allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack," a differe…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4418

Published Oct 9, 2012

Apache Axis2 allows remote attackers to forge messages and bypass authentication via an "XML Signature wrapping attack."

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0219

Published Oct 18, 2010

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, wh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1