CVE-2007-2353: Infoleak
Published Apr 30, 2007
·Updated
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
Affected Software
1 affected component
Apache Axis=1.0
Event History
Apr 30, 2007
CVE Published
10:19 PM
May 1, 2007
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2353?
CVE-2007-2353 is considered a medium severity vulnerability due to its potential to reveal sensitive information.
2
How do I fix CVE-2007-2353?
To fix CVE-2007-2353, upgrade Apache Axis to a version later than 1.0 where this issue is addressed.
3
What type of information can be exposed by CVE-2007-2353?
CVE-2007-2353 can expose the installation path of the Apache Axis server through exception messages.
4
Which software versions are affected by CVE-2007-2353?
CVE-2007-2353 affects Apache Axis version 1.0.
5
Can CVE-2007-2353 be exploited remotely?
Yes, CVE-2007-2353 can be exploited remotely by requesting a non-existent WSDL file.