CVE-2010-0219: Critical severity apache http server vulnerability
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0219?
CVE-2010-0219 is considered a high severity vulnerability due to the risk of remote code execution associated with a default password.
How do I fix CVE-2010-0219?
To fix CVE-2010-0219, change the default admin password from 'axis2' to a strong, unique password.
Which software versions are affected by CVE-2010-0219?
CVE-2010-0219 affects Apache Axis2 versions 1.3 to 1.6 and SAP BusinessObjects Enterprise XI 3.2.
What type of vulnerability is CVE-2010-0219?
CVE-2010-0219 is a security vulnerability that allows remote attackers to execute arbitrary code.
Is there a patch available for CVE-2010-0219?
There is no specific patch for CVE-2010-0219; the recommended action is to change the default password.