Apache / Axis2
6 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-5785 | axis2: Does not verify that the server hostname matches a domain name in the subject's CN or subjectAltName field of the x.509 certificate | MEDIUM | 5.8 | Nov 4, 2012 |
| CVE-2012-5351 | axis2: vulnerable to authentication bypass and forged messages due to a Signature exclusion attack | MEDIUM | 6.4 | Oct 9, 2012 |
| CVE-2012-4418 | axis2: vulnerable to XML signature wrapping attacks | MEDIUM | 5.8 | Oct 9, 2012 |
| CVE-2010-0219 | Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for t… | HIGH | 10.0 | Oct 18, 2010 |
| CVE-2010-1632 | Axis2: Does not properly reject DTDs in SOAP messages | HIGH | 7.5 | Jun 22, 2010 |
| CVE-2010-2103 | Axis2: Cross-site scripting (XSS) in the adminstration console | MEDIUM | 4.3 | May 27, 2010 |
Showing 1 to 6 of 6 CVEs