Back

HIGH

axis: Hard coded domain name in example web service named “StockQuoteService.jws” leading to remote code execution.

Published May 1, 2019

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (20)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published May 1, 2019
Updated Aug 4, 2024
Reserved Nov 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 9, 2019
GHSA-H9GJ-RQRW-X4FQ