High severity7.5NVD Advisory· Published May 1, 2019· Updated Jun 17, 2026
CVE-2019-0227
CVE-2019-0227
Description
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.axis:axisMaven | <= 1.4 | — |
axis:axisMaven | <= 1.4 | — |
Affected products
3- ghsa-coords2 versions
<= 1.4+ 1 more
- (no CPE)range: <= 1.4
- (no CPE)range: <= 1.4
- Apache/Apache Axis 1.4v5Range: Apache Axis 1.4
Patches
Vulnerability mechanics
References
19- www.oracle.com/security-alerts/cpuApr2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2020.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2020.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlnvdPatchThird Party AdvisoryWEB
- rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-h9gj-rqrw-x4fqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-0227ghsaADVISORY
- lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd@%3Cjava-user.axis.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3EnvdWEB
- lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c@%3Cannounce.apache.org%3EghsaWEB
- rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axisghsaWEB
- security.netapp.com/advisory/ntap-20240621-0006ghsaWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdWEB
- security.netapp.com/advisory/ntap-20240621-0006/nvd
News mentions
0No linked articles in our index yet.