Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-70275
HistorySep 11, 2023 - 12:00 a.m.

Apache Axis Input Validation Error Vulnerability

2023-09-1100:00:00
China National Vulnerability Database
www.cnvd.org.cn
12
apache axis
input validation
vulnerability
soap
java
c++
web services
application
dos
ssrf
rce
attack
exploitation

AI Score

9.3

Confidence

High

EPSS

0.003

Percentile

69.1%

Apache Axis is the United States Apache (Apache) Foundation of an open source , XML-based Web services architecture . The product contains a SOAP server implemented in Java and C++ languages , as well as a variety of utility services and APIs to generate and deploy Web services applications. Apache Axis has an input validation error vulnerability that arises from the failure of the program to properly handle untrusted input when passed to the ServiceFactory.getService method, which can be exploited by an attacker to expose an application to DoS, SSRF, or even cause an RCE attack.