Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.148543
Category:Web application abuses
Title:Apache Axis <= 1.4 Multiple Vulnerabilities
Summary:Apache Axis is prone to multiple vulnerabilities.
Description:Summary:
Apache Axis is prone to multiple vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2012-5784: SSL certificate validation security bypass

- CVE-2014-3596: Insecure certificate validation

- CVE-2018-8032: Cross-site scripting (XSS) in the default servlet/services

- CVE-2019-0227: Server-side request forgery (SSRF)

- CVE-2023-40743: Remote code execution (RCE)

- CVE-2023-51441: SSRF

Affected Software/OS:
Apache Axis version 1.4 and prior.

Note: The vulnerability announcement for CVE-2023-40743 from September 2023 and for CVE-2023-51441
from January 2024 mentions 'Apache Axis through 1.3' as being affected. But as the vendor states
that no fix is available it is assumed that the latest available version 1.4 (released on
April 22, 2006) is affected as well.

Solution:
No solution was made available by the vendor. General solution
options are to upgrade to a newer release, disable respective features, remove the product or
replace the product by another one.

Notes:

- Axis 1 has been EOL and the vendor recommend to migrate to a different SOAP engine, such as
Apache Axis2/Java

- Version 1.4 was released on April 22, 2006 and some of the flaws have been fixed only in the SVN
repository which could be used to mitigate these flaws

- The Apache Axis project does not expect to create an Axis 1.x release fixing these flaws

- If the remote installation has been build from the SVN sources or is covered via 'backports' of
a Linux distribution please create an override for this result

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-5784
BugTraq ID: 56408
http://www.securityfocus.com/bid/56408
http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf
https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c@%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5@%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832@%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780@%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d@%3Cjava-dev.axis.apache.org%3E
RedHat Security Advisories: RHSA-2013:0269
http://rhn.redhat.com/errata/RHSA-2013-0269.html
RedHat Security Advisories: RHSA-2013:0683
http://rhn.redhat.com/errata/RHSA-2013-0683.html
RedHat Security Advisories: RHSA-2014:0037
http://rhn.redhat.com/errata/RHSA-2014-0037.html
http://secunia.com/advisories/51219
SuSE Security Announcement: openSUSE-SU-2019:1497 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00007.html
SuSE Security Announcement: openSUSE-SU-2019:1526 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00022.html
XForce ISS Database: apache-axis-ssl-spoofing(79829)
https://exchange.xforce.ibmcloud.com/vulnerabilities/79829
Common Vulnerability Exposure (CVE) ID: CVE-2014-3596
1030745
http://www.securitytracker.com/id/1030745
61222
http://secunia.com/advisories/61222
69295
http://www.securityfocus.com/bid/69295
RHSA-2014:1193
http://rhn.redhat.com/errata/RHSA-2014-1193.html
[axis-java-dev] 20190503 [jira] [Comment Edited] (AXIS-2905) Insecure certificate validation CVE-2014-3596
https://lists.apache.org/thread.html/de2af12dcaba653d02b03235327ca4aa930401813a3cced8e151d29c%40%3Cjava-dev.axis.apache.org%3E
[axis-java-dev] 20190503 [jira] [Commented] (AXIS-2905) Insecure certificate validation CVE-2014-3596
https://lists.apache.org/thread.html/44d4e88a5fa8ae60deb752029afe9054da87c5f859caf296fcf585e5%40%3Cjava-dev.axis.apache.org%3E
[axis-java-dev] 20190907 [jira] [Commented] (AXIS-2905) Insecure certificate validation CVE-2014-3596
https://lists.apache.org/thread.html/8aa25c99eeb0693fc229ec87d1423b5ed5d58558618706d8aba1d832%40%3Cjava-dev.axis.apache.org%3E
[axis-java-dev] 20190909 [jira] [Commented] (AXIS-2905) Insecure certificate validation CVE-2014-3596
https://lists.apache.org/thread.html/5e6c92145deddcecf70c3604041dcbd615efa2d37632fc2b9c367780%40%3Cjava-dev.axis.apache.org%3E
[axis-java-dev] 20190909 [jira] [Resolved] (AXIS-2905) Insecure certificate validation CVE-2014-3596
https://lists.apache.org/thread.html/a308887782e05da7cf692e4851ae2bd429a038570cbf594e6631cc8d%40%3Cjava-dev.axis.apache.org%3E
[oss-security] 20140820 CVE-2014-3596 - Apache Axis 1 vulnerable to MITM attack
http://www.openwall.com/lists/oss-security/2014/08/20/2
apache-axis-cve20143596-spoofing(95377)
https://exchange.xforce.ibmcloud.com/vulnerabilities/95377
http://linux.oracle.com/errata/ELSA-2014-1193.html
https://issues.apache.org/jira/browse/AXIS-2905
https://www.oracle.com/security-alerts/cpujan2020.html
openSUSE-SU-2019:1497
openSUSE-SU-2019:1526
Common Vulnerability Exposure (CVE) ID: CVE-2018-8032
https://issues.apache.org/jira/browse/AXIS-2924
https://www.oracle.com/security-alerts/cpuApr2021.html
https://www.oracle.com/security-alerts/cpuapr2020.html
https://www.oracle.com/security-alerts/cpuapr2022.html
https://www.oracle.com/security-alerts/cpujan2021.html
https://www.oracle.com/security-alerts/cpujul2020.html
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
http://mail-archives.apache.org/mod_mbox/axis-java-dev/201807.mbox/%3CJIRA.13170716.1531060536000.93536.1531060560060@Atlassian.JIRA%3E
https://lists.apache.org/thread.html/d06ed5e4eeb77d00e8d594ec01ee8ee1cba173a01ac4b18f1579d041@%3Cjava-dev.axis.apache.org%3E
https://lists.apache.org/thread.html/3b89bc9e9d055db7eba8835ff6501f3f5db99d2a0928ec0be9b1d17b@%3Cjava-dev.axis.apache.org%3E
https://lists.debian.org/debian-lts-announce/2021/11/msg00015.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-0227
https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3E
https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd@%3Cjava-user.axis.apache.org%3E
Common Vulnerability Exposure (CVE) ID: CVE-2023-40743
https://github.com/apache/axis-axis1-java/commit/7e66753427466590d6def0125e448d2791723210
https://lists.apache.org/thread/gs0qgk2mgss7zfhzdd6ftfjvm4kp7v82
https://lists.debian.org/debian-lts-announce/2023/10/msg00025.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-51441
https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06
https://lists.apache.org/thread/8nrm5thop8f82pglx4o0jg8wmvy6d9yd
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.