VendorsApacheaxisany version
Vulnerabilities

Apache Software Foundation Axis any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2023-40743
Apache Axis 1.x (EOL) may allow RCE when untrusted input is passed to getService
Published 2023-09-05 · Modified
9.8EPSS 0.033
CVE-2023-51441
Apache Axis 1.x (EOL) may allow SSRF when untrusted input is passed to the service admin HTTP API
Published 2024-01-06 · Modified
7.2EPSS 0.012
CVE-2018-8032
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Published 2018-08-02 · Modified
6.1EPSS 0.106
CVE-2014-3596
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.
Published 2014-08-27 · Modified
5.8EPSS 0.092
CVE-2012-5784
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published 2012-11-04 · Modified
5.8EPSS 0.057