HIGH

CVE-2019-0227

CVSS v3

7.5

HIGH

EPSS Score

90.7%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Technical details

Published
5/1/2019
Exploit-DB
EDB-46682

Frequently asked questions

What is CVE-2019-0227?

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Is CVE-2019-0227 actively exploited?

Active exploitation of CVE-2019-0227 has not been confirmed. The EPSS score is 90.7%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-0227?

CVE-2019-0227 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-0227 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.