7.5

CVE-2019-0227

Exploit

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheAxis Version1.4
OracleApplication Testing Suite Version13.2.0.1
OracleApplication Testing Suite Version13.3.0.1
OracleBig Data Discovery Version1.6
OracleCommunications Design Studio Version7.3.4.3.0
OracleCommunications Design Studio Version7.3.5.5.0
OracleCommunications Design Studio Version7.4.0.4.0
OracleCommunications Design Studio Version7.4.1.1.0
OracleFinancial Services Funds Transfer Pricing Version >= 8.0.2 <= 8.0.7
OracleFlexcube Core Banking Version11.7.0
OracleFlexcube Core Banking Version11.8.0
OracleFlexcube Core Banking Version11.9.0
OracleFlexcube Core Banking Version11.10.0
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
OracleInternet Directory Version12.2.1.3.0
OracleInternet Directory Version12.2.1.4.0
OracleKnowledge Version >= 8.6.0 <= 8.6.3
OraclePrimavera Gateway Version16.2.11
OraclePrimavera Gateway Version17.12.6
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version16.1
OraclePrimavera Unifier Version16.2
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OracleRapid Planning Version12.1
OracleRapid Planning Version12.2
OracleReal-time Decision Server Version3.2.1.0
OracleRetail Order Broker Version15.0
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleSecure Global Desktop Version5.4
OracleSecure Global Desktop Version5.5
OracleSiebel Ui Framework Version <= 21.0
OracleTuxedo Version12.1.1.0.0
OracleTuxedo Version12.1.3
OracleWebcenter Portal Version12.2.1.3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 90.74% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 5.4 5.5 6.4
AV:A/AC:M/Au:N/C:P/I:P/A:P
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.