CVE-2019-0227 (CNNVD-201904-472)

HIGH 有利用代码
中文标题:
Apache Axis 代码问题漏洞
英文标题:
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa...
CVSS分数: 7.5
发布时间: 2019-05-01 20:03:49
漏洞类型: 代码问题
状态: PUBLISHED
数据质量分数: 0.30
数据版本: v4
漏洞描述
中文描述:

Apache Axis是美国阿帕奇(Apache)基金会的一个开源、基于XML的Web服务架构。该产品包含了Java和C++语言实现的SOAP服务器,以及各种公用服务及API,以生成和部署Web服务应用。 Apache Axis 1.4版本中存在代码问题漏洞。该漏洞源于网络系统或产品的代码开发过程中存在设计或实现不当的问题。

英文描述:

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CWE类型:
CWE-918
标签:
remote multiple David Yesland
受影响产品
厂商 产品 版本 版本范围 平台 CPE
Apache Apache Axis 1.4 Apache Axis 1.4 - - cpe:2.3:a:apache:apache_axis_1.4:apache_axis_1.4:*:*:*:*:*:*:*
apache axis 1.4 - - cpe:2.3:a:apache:axis:1.4:*:*:*:*:*:*:*
oracle agile_engineering_data_management 6.2.1.0 - - cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
oracle agile_product_lifecycle_management 9.3.3 - - cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*
oracle application_testing_suite 13.2.0.1 - - cpe:2.3:a:oracle:application_testing_suite:13.2.0.1:*:*:*:*:*:*:*
oracle application_testing_suite 13.3.0.1 - - cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
oracle big_data_discovery 1.6 - - cpe:2.3:a:oracle:big_data_discovery:1.6:*:*:*:*:*:*:*
oracle communications_asap_cartridges 7.2 - - cpe:2.3:a:oracle:communications_asap_cartridges:7.2:*:*:*:*:*:*:*
oracle communications_asap_cartridges 7.3 - - cpe:2.3:a:oracle:communications_asap_cartridges:7.3:*:*:*:*:*:*:*
oracle communications_design_studio 7.3.4.3.0 - - cpe:2.3:a:oracle:communications_design_studio:7.3.4.3.0:*:*:*:*:*:*:*
oracle communications_design_studio 7.3.5.5.0 - - cpe:2.3:a:oracle:communications_design_studio:7.3.5.5.0:*:*:*:*:*:*:*
oracle communications_design_studio 7.4.0.4.0 - - cpe:2.3:a:oracle:communications_design_studio:7.4.0.4.0:*:*:*:*:*:*:*
oracle communications_design_studio 7.4.1.1.0 - - cpe:2.3:a:oracle:communications_design_studio:7.4.1.1.0:*:*:*:*:*:*:*
oracle communications_element_manager 8.0.0 - - cpe:2.3:a:oracle:communications_element_manager:8.0.0:*:*:*:*:*:*:*
oracle communications_element_manager 8.1.0 - - cpe:2.3:a:oracle:communications_element_manager:8.1.0:*:*:*:*:*:*:*
oracle communications_element_manager 8.1.1 - - cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
oracle communications_element_manager 8.2.0 - - cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
oracle communications_network_integrity 7.3.5 - - cpe:2.3:a:oracle:communications_network_integrity:7.3.5:*:*:*:*:*:*:*
oracle communications_network_integrity 7.3.6 - - cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
oracle communications_order_and_service_management 7.3.0.0.0 - - cpe:2.3:a:oracle:communications_order_and_service_management:7.3.0.0.0:*:*:*:*:*:*:*
oracle communications_order_and_service_management 7.4 - - cpe:2.3:a:oracle:communications_order_and_service_management:7.4:*:*:*:*:*:*:*
oracle communications_session_report_manager 8.0.0 - - cpe:2.3:a:oracle:communications_session_report_manager:8.0.0:*:*:*:*:*:*:*
oracle communications_session_report_manager 8.1.0 - - cpe:2.3:a:oracle:communications_session_report_manager:8.1.0:*:*:*:*:*:*:*
oracle communications_session_report_manager 8.1.1 - - cpe:2.3:a:oracle:communications_session_report_manager:8.1.1:*:*:*:*:*:*:*
oracle communications_session_report_manager 8.2.0 - - cpe:2.3:a:oracle:communications_session_report_manager:8.2.0:*:*:*:*:*:*:*
oracle communications_session_route_manager 8.0.0 - - cpe:2.3:a:oracle:communications_session_route_manager:8.0.0:*:*:*:*:*:*:*
oracle communications_session_route_manager 8.1.0 - - cpe:2.3:a:oracle:communications_session_route_manager:8.1.0:*:*:*:*:*:*:*
oracle communications_session_route_manager 8.1.1 - - cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*
oracle communications_session_route_manager 8.2.0 - - cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*
oracle endeca_information_discovery_studio 3.2.0 - - cpe:2.3:a:oracle:endeca_information_discovery_studio:3.2.0:*:*:*:*:*:*:*
oracle enterprise_manager_base_platform 12.1.0.5 - - cpe:2.3:a:oracle:enterprise_manager_base_platform:12.1.0.5:*:*:*:*:*:*:*
oracle enterprise_manager_base_platform 13.3.0.0 - - cpe:2.3:a:oracle:enterprise_manager_base_platform:13.3.0.0:*:*:*:*:*:*:*
oracle enterprise_manager_for_fusion_middleware 12.1.0.5 - - cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:12.1.0.5:*:*:*:*:*:*:*
oracle financial_services_analytical_applications_infrastructure * - - cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*
oracle financial_services_compliance_regulatory_reporting * - - cpe:2.3:a:oracle:financial_services_compliance_regulatory_reporting:*:*:*:*:*:*:*:*
oracle financial_services_funds_transfer_pricing * - - cpe:2.3:a:oracle:financial_services_funds_transfer_pricing:*:*:*:*:*:*:*:*
oracle flexcube_core_banking 11.7.0 - - cpe:2.3:a:oracle:flexcube_core_banking:11.7.0:*:*:*:*:*:*:*
oracle flexcube_core_banking 11.8.0 - - cpe:2.3:a:oracle:flexcube_core_banking:11.8.0:*:*:*:*:*:*:*
oracle flexcube_core_banking 11.9.0 - - cpe:2.3:a:oracle:flexcube_core_banking:11.9.0:*:*:*:*:*:*:*
oracle flexcube_core_banking 11.10.0 - - cpe:2.3:a:oracle:flexcube_core_banking:11.10.0:*:*:*:*:*:*:*
oracle flexcube_private_banking 12.0.0 - - cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
oracle flexcube_private_banking 12.1.0 - - cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.0 - - cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
oracle hospitality_guest_access 4.2.1 - - cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.1 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.2 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
oracle instantis_enterprisetrack 17.3 - - cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
oracle internet_directory 12.2.1.3.0 - - cpe:2.3:a:oracle:internet_directory:12.2.1.3.0:*:*:*:*:*:*:*
oracle internet_directory 12.2.1.4.0 - - cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*
oracle knowledge * - - cpe:2.3:a:oracle:knowledge:*:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_human_capital_management_human_resources 7.3.5 - - cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:7.3.5:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_human_capital_management_human_resources 7.3.6 - - cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:7.3.6:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_human_capital_management_human_resources 9.2 - - cpe:2.3:a:oracle:peoplesoft_enterprise_human_capital_management_human_resources:9.2:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.56 - - cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.56:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.57 - - cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.57:*:*:*:*:*:*:*
oracle peoplesoft_enterprise_peopletools 8.58 - - cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58:*:*:*:*:*:*:*
oracle policy_automation_connector_for_siebel 10.4.6 - - cpe:2.3:a:oracle:policy_automation_connector_for_siebel:10.4.6:*:*:*:*:*:*:*
oracle primavera_gateway 16.2.11 - - cpe:2.3:a:oracle:primavera_gateway:16.2.11:*:*:*:*:*:*:*
oracle primavera_gateway 17.12.6 - - cpe:2.3:a:oracle:primavera_gateway:17.12.6:*:*:*:*:*:*:*
oracle primavera_unifier * - - cpe:2.3:a:oracle:primavera_unifier:*:*:*:*:*:*:*:*
oracle primavera_unifier 16.1 - - cpe:2.3:a:oracle:primavera_unifier:16.1:*:*:*:*:*:*:*
oracle primavera_unifier 16.2 - - cpe:2.3:a:oracle:primavera_unifier:16.2:*:*:*:*:*:*:*
oracle primavera_unifier 18.8 - - cpe:2.3:a:oracle:primavera_unifier:18.8:*:*:*:*:*:*:*
oracle primavera_unifier 19.12 - - cpe:2.3:a:oracle:primavera_unifier:19.12:*:*:*:*:*:*:*
oracle rapid_planning 12.1 - - cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*
oracle rapid_planning 12.2 - - cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*
oracle real-time_decision_server 3.2.1.0 - - cpe:2.3:a:oracle:real-time_decision_server:3.2.1.0:*:*:*:*:*:*:*
oracle retail_order_broker 15.0 - - cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
oracle retail_order_broker 16.0 - - cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*
oracle retail_order_broker 18.0 - - cpe:2.3:a:oracle:retail_order_broker:18.0:*:*:*:*:*:*:*
oracle retail_xstore_point_of_service 7.1 - - cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*
oracle secure_global_desktop 5.4 - - cpe:2.3:a:oracle:secure_global_desktop:5.4:*:*:*:*:*:*:*
oracle secure_global_desktop 5.5 - - cpe:2.3:a:oracle:secure_global_desktop:5.5:*:*:*:*:*:*:*
oracle siebel_ui_framework * - - cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*
oracle tuxedo 12.1.1.0.0 - - cpe:2.3:a:oracle:tuxedo:12.1.1.0.0:*:*:*:*:*:*:*
oracle tuxedo 12.1.3 - - cpe:2.3:a:oracle:tuxedo:12.1.3:*:*:*:*:*:*:*
oracle webcenter_portal 12.2.1.3.0 - - cpe:2.3:a:oracle:webcenter_portal:12.2.1.3.0:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 OTHER
cve.org
访问
[announce] 20200131 Apache Software Foundation Security Report: 2019 mailing-list
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
[axis-java-user] 20210928 [Axis2] Migration Issues mailing-list
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
无标题 OTHER
cve.org
访问
ExploitDB EDB-46682 EXPLOIT
exploitdb
访问
Download Exploit EDB-46682 EXPLOIT
exploitdb
访问
CVE Reference: CVE-2019-0227 ADVISORY
cve.org
访问
CVSS评分详情
7.5
HIGH
CVSS向量: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS版本: 3.1
机密性
HIGH
完整性
HIGH
可用性
HIGH
时间信息
发布时间:
2019-05-01 20:03:49
修改时间:
2024-08-04 17:44:15
创建时间:
2025-11-11 15:35:24
更新时间:
2025-11-11 16:51:03
利用信息
此漏洞有可利用代码!
利用代码数量: 1
利用来源:
未知
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2019-0227 2025-11-11 15:19:56 2025-11-11 07:35:24
NVD nvd_CVE-2019-0227 2025-11-11 14:56:22 2025-11-11 07:43:58
CNNVD cnnvd_CNNVD-201904-472 2025-11-11 15:10:11 2025-11-11 07:54:29
EXPLOITDB exploitdb_EDB-46682 2025-11-11 15:05:28 2025-11-11 08:51:03
版本与语言
当前版本: v4
主要语言: EN
支持语言:
EN ZH
其他标识符:
:
:
安全公告
暂无安全公告信息
变更历史
v4 EXPLOITDB
2025-11-11 16:51:03
references_count: 13 → 16; tags_count: 0 → 3; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
  • references_count: 13 -> 16
  • tags_count: 0 -> 3
  • data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3 CNNVD
2025-11-11 15:54:29
vulnerability_type: 未提取 → 代码问题; cnnvd_id: 未提取 → CNNVD-201904-472; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 代码问题
  • cnnvd_id: 未提取 -> CNNVD-201904-472
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:43:58
severity: SeverityLevel.MEDIUM → SeverityLevel.HIGH; cvss_score: 未提取 → 7.5; cvss_vector: NOT_EXTRACTED → CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H; cvss_version: NOT_EXTRACTED → 3.1; affected_products_count: 1 → 77; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
  • cvss_score: 未提取 -> 7.5
  • cvss_vector: NOT_EXTRACTED -> CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • cvss_version: NOT_EXTRACTED -> 3.1
  • affected_products_count: 1 -> 77
  • data_sources: ['cve'] -> ['cve', 'nvd']