CVE-2019-0227

Published on: 05/01/2019 12:00:00 AM UTC

Last Modified on: 07/25/2022 07:09:16 PM UTC

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Certain versions of Axis from Apache contain the following vulnerability:

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

  • CVE-2019-0227 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.
  • Affected Vendor/Software: URL Logo Apache - Apache Axis 1.4 version Apache Axis 1.4

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
ADJACENT_NETWORK HIGH NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED HIGH HIGH HIGH

CVSS2 Score: 5.4 - MEDIUM

Access
Vector
Access
Complexity
Authentication
ADJACENT_NETWORK MEDIUM NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
PARTIAL PARTIAL PARTIAL

CVE References

Description Tags Link
Pony Mail! lists.apache.org
text/html
URL Logo MLIST [axis-java-user] 20210928 [Axis2] Migration Issues
Oracle Critical Patch Update Advisory - July 2020 Third Party Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujul2020.html
Oracle Critical Patch Update Advisory - April 2022 www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpuapr2022.html
Pony Mail! Mailing List
Vendor Advisory
lists.apache.org
text/html
URL Logo MLIST [announce] 20200131 Apache Software Foundation Security Report: 2019
Oracle Critical Patch Update Advisory - October 2021 www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpuoct2021.html
CVE-2019-0227: Expired Domain to RCE in Apache Axis Exploit
Third Party Advisory
rhinosecuritylabs.com
text/html
URL Logo MISC rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/
Oracle Critical Patch Update - October 2019 Third Party Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
Oracle Critical Patch Update Advisory - January 2020 Third Party Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujan2020.html
Oracle Critical Patch Update Advisory - April 2020 Third Party Advisory
www.oracle.com
text/html
URL Logo N/A N/A
Oracle Critical Patch Update Advisory - July 2022 www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujul2022.html
Oracle Critical Patch Update Advisory - April 2021 www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpuApr2021.html
Oracle Critical Patch Update Advisory - January 2021 Third Party Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujan2021.html

Related QID Numbers

  • 980289 Java (maven) Security Update for org.apache.axis:axis (GHSA-h9gj-rqrw-x4fq)

Exploit/POC from Github

PoC for exploiting CVE-2019-0227 : A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 di…

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationApacheAxis1.4AllAllAll
ApplicationApacheAxis1.4AllAllAll
ApplicationOracleAgile Engineering Data Management6.2.1.0AllAllAll
ApplicationOracleAgile Product Lifecycle Management Framework9.3.3AllAllAll
ApplicationOracleApplication Testing Suite13.2.0.1AllAllAll
ApplicationOracleApplication Testing Suite13.3.0.1AllAllAll
ApplicationOracleBig Data Discovery1.6AllAllAll
ApplicationOracleCommunications Asap Cartridges7.2AllAllAll
ApplicationOracleCommunications Asap Cartridges7.3AllAllAll
ApplicationOracleCommunications Design Studio7.3.4.3.0AllAllAll
ApplicationOracleCommunications Design Studio7.3.5.5.0AllAllAll
ApplicationOracleCommunications Design Studio7.4.0.4.0AllAllAll
ApplicationOracleCommunications Design Studio7.4.1.1.0AllAllAll
ApplicationOracleCommunications Element Manager8.0.0AllAllAll
ApplicationOracleCommunications Element Manager8.1.0AllAllAll
ApplicationOracleCommunications Element Manager8.1.1AllAllAll
ApplicationOracleCommunications Element Manager8.2.0AllAllAll
ApplicationOracleCommunications Network Integrity7.3.5AllAllAll
ApplicationOracleCommunications Network Integrity7.3.6AllAllAll
ApplicationOracleCommunications Order And Service Management7.3.0.0.0AllAllAll
ApplicationOracleCommunications Order And Service Management7.4AllAllAll
ApplicationOracleCommunications Session Report Manager8.0.0AllAllAll
ApplicationOracleCommunications Session Report Manager8.1.0AllAllAll
ApplicationOracleCommunications Session Report Manager8.1.1AllAllAll
ApplicationOracleCommunications Session Report Manager8.2.0AllAllAll
ApplicationOracleCommunications Session Route Manager8.0.0AllAllAll
ApplicationOracleCommunications Session Route Manager8.1.0AllAllAll
ApplicationOracleCommunications Session Route Manager8.1.1AllAllAll
ApplicationOracleCommunications Session Route Manager8.2.0AllAllAll
ApplicationOracleEndeca Information Discovery Studio3.2.0AllAllAll
ApplicationOracleEnterprise Manager Base Platform12.1.0.5AllAllAll
ApplicationOracleEnterprise Manager Base Platform13.3.0.0AllAllAll
ApplicationOracleEnterprise Manager For Fusion Middleware12.1.0.5AllAllAll
ApplicationOracleFinancial Services Analytical Applications InfrastructureAllAllAllAll
ApplicationOracleFinancial Services Analytical Applications InfrastructureAllAllAllAll
ApplicationOracleFinancial Services Compliance Regulatory ReportingAllAllAllAll
ApplicationOracleFinancial Services Funds Transfer PricingAllAllAllAll
ApplicationOracleFlexcube Core Banking11.10.0AllAllAll
ApplicationOracleFlexcube Core Banking11.7.0AllAllAll
ApplicationOracleFlexcube Core Banking11.8.0AllAllAll
ApplicationOracleFlexcube Core Banking11.9.0AllAllAll
ApplicationOracleFlexcube Private Banking12.0.0AllAllAll
ApplicationOracleFlexcube Private Banking12.1.0AllAllAll
ApplicationOracleHospitality Guest Access4.2.0AllAllAll
ApplicationOracleHospitality Guest Access4.2.1AllAllAll
ApplicationOracleInstantis Enterprisetrack17.1AllAllAll
ApplicationOracleInstantis Enterprisetrack17.2AllAllAll
ApplicationOracleInstantis Enterprisetrack17.3AllAllAll
ApplicationOracleInternet Directory12.2.1.3.0AllAllAll
ApplicationOracleInternet Directory12.2.1.4.0AllAllAll
ApplicationOracleKnowledgeAllAllAllAll
ApplicationOraclePeoplesoft Enterprise Human Capital Management Human Resources7.3.5AllAllAll
ApplicationOraclePeoplesoft Enterprise Human Capital Management Human Resources7.3.6AllAllAll
ApplicationOraclePeoplesoft Enterprise Human Capital Management Human Resources9.2AllAllAll
ApplicationOraclePeoplesoft Enterprise Peopletools8.56AllAllAll
ApplicationOraclePeoplesoft Enterprise Peopletools8.57AllAllAll
ApplicationOraclePeoplesoft Enterprise Peopletools8.58AllAllAll
ApplicationOraclePolicy Automation Connector For Siebel10.4.6AllAllAll
ApplicationOraclePrimavera Gateway16.2.11AllAllAll
ApplicationOraclePrimavera Gateway17.12.6AllAllAll
ApplicationOraclePrimavera Unifier16.1AllAllAll
ApplicationOraclePrimavera Unifier16.2AllAllAll
ApplicationOraclePrimavera Unifier18.8AllAllAll
ApplicationOraclePrimavera Unifier19.12AllAllAll
ApplicationOraclePrimavera UnifierAllAllAllAll
ApplicationOracleRapid Planning12.1AllAllAll
ApplicationOracleRapid Planning12.2AllAllAll
ApplicationOracleReal-time Decision Server3.2.1.0AllAllAll
ApplicationOracleRetail Order Broker15.0AllAllAll
ApplicationOracleRetail Order Broker16.0AllAllAll
ApplicationOracleRetail Order Broker18.0AllAllAll
ApplicationOracleRetail Xstore Point Of Service7.1AllAllAll
ApplicationOracleSecure Global Desktop5.4AllAllAll
ApplicationOracleSecure Global Desktop5.5AllAllAll
ApplicationOracleSiebel Ui FrameworkAllAllAllAll
ApplicationOracleTuxedo12.1.1.0.0AllAllAll
ApplicationOracleTuxedo12.1.3AllAllAll
ApplicationOracleWebcenter Portal12.2.1.3.0AllAllAll
  • cpe:2.3:a:apache:axis:1.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:apache:axis:1.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:agile_product_lifecycle_management_framework:9.3.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:big_data_discovery:1.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_asap_cartridges:7.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_asap_cartridges:7.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_design_studio:7.3.4.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_design_studio:7.3.5.5.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_design_studio:7.4.0.4.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_design_studio:7.4.1.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_element_manager:8.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_element_manager:8.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_network_integrity:7.3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_order_and_service_management:7.3.0.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_order_and_service_management:7.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_report_manager:8.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_report_manager:8.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_route_manager:8.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_route_manager:8.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:12.1.0.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_compliance_regulatory_reporting:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_core_banking:11.10.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_core_banking:11.7.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_core_banking:11.8.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_core_banking:11.9.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:internet_directory:12.2.1.3.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:knowledge:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:7.3.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:7.3.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:9.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_gateway:16.2.11:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_gateway:17.12.6:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:real-time_decision_server:3.2.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_order_broker:18.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:secure_global_desktop:5.4:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:secure_global_desktop:5.5:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:tuxedo:12.1.1.0.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @LinInfoSec Axis2 - CVE-2019-0227: rhinosecuritylabs.com/application-se… 2021-09-29 11:16:01
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report