CVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 89.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 89.87% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- apache/axis2 · sap/businessobjects
- Source
- cret@cert.org
References
- http://retrogod.altervista.org/9sg_ca_d2d.html
- http://secunia.com/advisories/41799Vendor Advisory
- http://secunia.com/advisories/42763
- http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdfExploit
- http://www.exploit-db.com/exploits/15869
- http://www.kb.cert.org/vuls/id/989719US Government Resource
- http://www.osvdb.org/70233
- http://www.rapid7.com/security-center/advisories/R7-0037.jspExploit
- http://www.securityfocus.com/archive/1/514284/100/0/threaded
- http://www.securitytracker.com/id?1024929
- http://www.vupen.com/english/advisories/2010/2673Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62523
- https://kb.juniper.net/KB27373
- https://service.sap.com/sap/support/notes/1432881Patch
- http://retrogod.altervista.org/9sg_ca_d2d.html
- http://secunia.com/advisories/41799Vendor Advisory
- http://secunia.com/advisories/42763
- http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdfExploit
- http://www.exploit-db.com/exploits/15869
- http://www.kb.cert.org/vuls/id/989719US Government Resource
- http://www.osvdb.org/70233
- http://www.rapid7.com/security-center/advisories/R7-0037.jspExploit
- http://www.securityfocus.com/archive/1/514284/100/0/threaded
- http://www.securitytracker.com/id?1024929
- http://www.vupen.com/english/advisories/2010/2673Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62523
- https://kb.juniper.net/KB27373
- https://service.sap.com/sap/support/notes/1432881Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.