Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Agile Engineering Data Management Subscribe
Agile Product Lifecycle Management Subscribe
Application Testing Suite Subscribe
Big Data Discovery Subscribe
Communications Asap Cartridges Subscribe
Communications Design Studio Subscribe
Communications Element Manager Subscribe
Communications Network Integrity Subscribe
Communications Order And Service Management Subscribe
Communications Session Report Manager Subscribe
Communications Session Route Manager Subscribe
Endeca Information Discovery Studio Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Manager For Fusion Middleware Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Financial Services Compliance Regulatory Reporting Subscribe
Financial Services Funds Transfer Pricing Subscribe
Flexcube Core Banking Subscribe
Flexcube Private Banking Subscribe
Hospitality Guest Access Subscribe
Instantis Enterprisetrack Subscribe
Internet Directory Subscribe
Knowledge Subscribe
Peoplesoft Enterprise Human Capital Management Human Resources Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Policy Automation Connector For Siebel Subscribe
Primavera Gateway Subscribe
Primavera Unifier Subscribe
Rapid Planning Subscribe
Real-time Decision Server Subscribe
Retail Order Broker Subscribe
Retail Xstore Point Of Service Subscribe
Secure Global Desktop Subscribe
Siebel Ui Framework Subscribe
Webcenter Portal Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2821-1 axis security update
EUVD EUVD EUVD-2018-0560 Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Github GHSA Github GHSA GHSA-96jq-75wh-2658 Moderate severity vulnerability that affects apache axis
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 May 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_framework:9.3.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management Framework
Oracle agile Product Lifecycle Management

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-16T16:29:01.816Z

Reserved: 2018-03-09T00:00:00

Link: CVE-2018-8032

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-08-02T13:29:00.363

Modified: 2025-05-08T18:13:51.353

Link: CVE-2018-8032

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-07-08T00:00:00Z

Links: CVE-2018-8032 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses