Axis

Vendor:

First CVE: Apr 30, 2007 · Active for 19 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Axis over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2007
19 years ago
Most Recent CVE
Jan 6, 2024
930 days ago

CVE Severity & Scoring

Axis7 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (42.9%)
Unknown3 (42.9%)
Physical0 (0.0%)
Adjacent Network1 (14.3%)
Attack Complexity
Low3 (42.9%)
High1 (14.3%)
Unknown3 (42.9%)
User Interaction
None3 (42.9%)
Unknown3 (42.9%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High1 (14.3%)
None3 (42.9%)
Unknown3 (42.9%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projec
May 1, 20197.582NOYES
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception messa
Apr 30, 20075.035NOYES
** UNSUPPORTED WHEN ASSIGNED ** When integrating Apache Axis 1.x in an application, it may not have been obvious that looking up a service through "ServiceFactory.getService" allow
Sep 5, 20239.829NONO
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Aug 2, 20186.126NONO
** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects Ap
Jan 6, 20247.222NONO
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and
Nov 4, 20125.822NONO
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field
Aug 27, 20145.819NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
28.6% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Axis

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.417.586.5%01
1.325.87.4%00
1.2.125.87.4%00
1.225.87.4%00
1.125.87.4%00
1.035.79.7%01