HIGH
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service
Published Oct 18, 2010
10.0
HIGHCVSS 2.0
EPSS 90.85%
Description
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://retrogod.altervista.org/9sg_ca_d2d.html x_refsource_MISC
- http://secunia.com/advisories/41799 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/42763 third-party-advisoryx_refsource_SECUNIA
- http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf x_refsource_MISCExploit
- http://www.exploit-db.com/exploits/15869 exploitx_refsource_EXPLOIT-DB
- http://www.kb.cert.org/vuls/id/989719 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.osvdb.org/70233 vdb-entryx_refsource_OSVDB
- http://www.rapid7.com/security-center/advisories/R7-0037.jsp x_refsource_MISCExploit
- http://www.securityfocus.com/archive/1/514284/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securitytracker.com/id?1024929 vdb-entryx_refsource_SECTRACK
- http://www.vupen.com/english/advisories/2010/2673 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/62523 vdb-entryx_refsource_XF
- https://kb.juniper.net/KB27373 x_refsource_CONFIRM
- https://service.sap.com/sap/support/notes/1432881 x_refsource_MISCPatch
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Oct 18, 2010
Updated Aug 7, 2024
Reserved Jan 6, 2010
Link CVE-2010-0219
CISA Vulnrichment
Updated n/a