6.1

CVE-2018-8032

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAxis Version >= 1.0 <= 1.4
OracleApplication Testing Suite Version13.2.0.1
OracleApplication Testing Suite Version13.3.0.1
OracleBig Data Discovery Version1.6
OracleCommunications Design Studio Version7.3.4.3.0
OracleCommunications Design Studio Version7.3.5.5.0
OracleCommunications Design Studio Version7.4.0.4.0
OracleCommunications Design Studio Version7.4.1.1.0
OracleFinancial Services Funds Transfer Pricing Version >= 8.0.2 <= 8.0.7
OracleFlexcube Core Banking Version11.7.0
OracleFlexcube Core Banking Version11.8.0
OracleFlexcube Core Banking Version11.9.0
OracleFlexcube Core Banking Version11.10.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
OracleInternet Directory Version12.2.1.3.0
OracleInternet Directory Version12.2.1.4.0
OracleKnowledge Version >= 8.6.0 <= 8.6.3
OraclePrimavera Gateway Version16.2.11
OraclePrimavera Gateway Version17.12.6
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleReal-time Decision Server Version3.2.1.0
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleSecure Global Desktop Version5.4
OracleSecure Global Desktop Version5.5
OracleSiebel Ui Framework Version <= 21.0
OracleTuxedo Version12.1.1.0.0
OracleTuxedo Version12.1.3
OracleWebcenter Portal Version12.2.1.3.0
DebianDebian Linux Version9.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.34% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

https://issues.apache.org/jira/browse/AXIS-2924
Patch
Vendor Advisory
Issue Tracking