SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-0227

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006.

HIGH 7.5EPSS 91.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 91.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
91.94% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-918
Affected
apache/axis · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/application testing suite · oracle/big data discovery · oracle/communications asap cartridges · oracle/communications design studio · oracle/communications element manager · oracle/communications network integrity · oracle/communications order and service management · oracle/communications session report manager · oracle/communications session route manager · oracle/endeca information discovery studio · oracle/enterprise manager base platform · oracle/enterprise manager for fusion middleware · oracle/financial services analytical applications infrastructure · oracle/financial services compliance regulatory reporting · oracle/financial services funds transfer pricing · oracle/flexcube core banking · oracle/flexcube private banking · +17 more
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.