QID 980104

QID 980104: Java (maven) Security Update for axis:axis (GHSA-96jq-75wh-2658)

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-96jq-75wh-2658 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980104

    Software Advisories
    Advisory ID Software Component Link
    GHSA-96jq-75wh-2658 axis:axis URL Logo github.com/advisories/GHSA-96jq-75wh-2658
    GHSA-96jq-75wh-2658 org.apache.axis:axis URL Logo github.com/advisories/GHSA-96jq-75wh-2658