Medium severity6.1NVD Advisory· Published Aug 2, 2018· Updated Jun 17, 2026
CVE-2018-8032
CVE-2018-8032
Description
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.axis:axisMaven | <= 1.4 | — |
axis:axisMaven | <= 1.4 | — |
Affected products
8- ghsa-coords7 versionspkg:maven/axis/axispkg:maven/org.apache.axis/axispkg:rpm/suse/axis&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/axis&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/axis&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/axis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/axis&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3
<= 1.4+ 6 more
- (no CPE)range: <= 1.4
- (no CPE)range: <= 1.4
- (no CPE)range: < 1.4-5.3.1
- (no CPE)range: < 1.4-236.236.44.9.1
- (no CPE)range: < 1.4-290.3.1
- (no CPE)range: < 1.4-236.236.44.9.1
- (no CPE)range: < 1.4-290.3.1
- Range: 1.x up to and including 1.4
Patches
Vulnerability mechanics
References
21- issues.apache.org/jira/browse/AXIS-2924nvdIssue TrackingPatchVendor AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-96jq-75wh-2658ghsaADVISORY
- lists.debian.org/debian-lts-announce/2021/11/msg00015.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-8032ghsaADVISORY
- www.oracle.com/security-alerts/cpuApr2021.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2020.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2020.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2021.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdThird Party AdvisoryWEB
- mail-archives.apache.org/mod_mbox/axis-java-dev/201807.mbox/%3CJIRA.13170716.1531060536000.93536.1531060560060%40Atlassian.JIRA%3EnvdWEB
- mail-archives.apache.org/mod_mbox/axis-java-dev/201807.mbox/%3CJIRA.13170716.1531060536000.93536.1531060560060@Atlassian.JIRA%3EghsaWEB
- lists.apache.org/thread.html/3b89bc9e9d055db7eba8835ff6501f3f5db99d2a0928ec0be9b1d17b%40%3Cjava-dev.axis.apache.org%3EnvdWEB
- lists.apache.org/thread.html/3b89bc9e9d055db7eba8835ff6501f3f5db99d2a0928ec0be9b1d17b@%3Cjava-dev.axis.apache.org%3EghsaWEB
- lists.apache.org/thread.html/d06ed5e4eeb77d00e8d594ec01ee8ee1cba173a01ac4b18f1579d041%40%3Cjava-dev.axis.apache.org%3EnvdWEB
- lists.apache.org/thread.html/d06ed5e4eeb77d00e8d594ec01ee8ee1cba173a01ac4b18f1579d041@%3Cjava-dev.axis.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20240621-0006ghsaWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdWEB
- security.netapp.com/advisory/ntap-20240621-0006/nvd
News mentions
0No linked articles in our index yet.