CVE-2010-0219 describes a critical vulnerability in Apache Axis2, affecting products like SAP BusinessObjects Enterprise XI 3.2 and CA ARCserve D2D r15, where a default "axis2" password for the admin account allows remote attackers to execute arbitrary code by uploading crafted web services. This vulnerability carries a CVSS score of 10.0, indicating a severe risk with network-based exploitation, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, exploit intelligence confirms readily available Metasploit modules and Nuclei templates, along with multiple ExploitDB entries, demonstrating active exploit development and public awareness, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3CPE matchmatch criteria | cpe:2.3:a:apache:axis2:1.3:*:*:*:*:*:*:* | ||
1.4CPE matchmatch criteria | cpe:2.3:a:apache:axis2:1.4:*:*:*:*:*:*:* | ||
1.4.1CPE matchmatch criteria | cpe:2.3:a:apache:axis2:1.4.1:*:*:*:*:*:*:* | ||
1.5CPE matchmatch criteria | cpe:2.3:a:apache:axis2:1.5:*:*:*:*:*:*:* | ||
1.5.1CPE matchmatch criteria | cpe:2.3:a:apache:axis2:1.5.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.