CVE-2019-0227: SSRF
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
Other sources
Apache Axis is vulnerable to server-side request forgery, caused by an expired hard coded domain, used in a default example service named StockQuoteService.jws. By using a man-in-the-middle attack to force an HTTP request, a remote attacker could exploit this vulnerability to conduct an SSRF attack, allowing the attacker to execute arbitrary code on the system.
— IBM
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0227?
The severity of CVE-2019-0227 is classified as high due to its potential for Server Side Request Forgery (SSRF) exploits.
How do I fix CVE-2019-0227?
To fix CVE-2019-0227, users are advised to upgrade to a version of Apache Axis later than 1.4 or build the software from source.
What are the affected software versions for CVE-2019-0227?
CVE-2019-0227 affects Apache Axis version 1.4 and certain Oracle and IBM products that integrate this library.
Is CVE-2019-0227 exploitable remotely?
Yes, CVE-2019-0227 can be exploited remotely due to its nature as a Server Side Request Forgery vulnerability.
What is the impact of a successful exploit of CVE-2019-0227?
A successful exploit of CVE-2019-0227 could allow an attacker to make unauthorized requests to internal systems and potentially gain access to sensitive data.