Apache Software Foundation Axis2.5.2

CPE Details

Apache Software Foundation Axis2.5.2
1.5.2
2010-06-23
13h50 +00:00
2012-11-13
22h59 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:apache:axis2:1.5.2:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

axis2

Version

1.5.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2012-5785 2012-11-04 21h00 +00:00 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
5.8
CVE-2010-0219 2010-10-18 14h00 +00:00 Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
10