Apache Software Foundation Axis2.6

CPE Details

Apache Software Foundation Axis2.6
1.6
2010-06-23
13h50 +00:00
2012-11-13
22h59 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:apache:axis2:1.6:*:*:*:*:*:*:*

Informations

Vendor

apache

Product

axis2

Version

1.6

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2012-5785 2012-11-04 21h00 +00:00 Apache Axis2/Java 1.6.2 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
5.8
CVE-2010-0219 2010-10-18 14h00 +00:00 Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
10