A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Project Subscriptions

Vendors Products
Agile Engineering Data Management Subscribe
Agile Product Lifecycle Management Subscribe
Application Testing Suite Subscribe
Big Data Discovery Subscribe
Communications Asap Cartridges Subscribe
Communications Design Studio Subscribe
Communications Element Manager Subscribe
Communications Network Integrity Subscribe
Communications Order And Service Management Subscribe
Communications Session Report Manager Subscribe
Communications Session Route Manager Subscribe
Endeca Information Discovery Studio Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Manager For Fusion Middleware Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Financial Services Compliance Regulatory Reporting Subscribe
Financial Services Funds Transfer Pricing Subscribe
Flexcube Core Banking Subscribe
Flexcube Private Banking Subscribe
Hospitality Guest Access Subscribe
Instantis Enterprisetrack Subscribe
Internet Directory Subscribe
Knowledge Subscribe
Peoplesoft Enterprise Human Capital Management Human Resources Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Policy Automation Connector For Siebel Subscribe
Primavera Gateway Subscribe
Primavera Unifier Subscribe
Rapid Planning Subscribe
Real-time Decision Server Subscribe
Retail Order Broker Subscribe
Retail Xstore Point Of Service Subscribe
Secure Global Desktop Subscribe
Siebel Ui Framework Subscribe
Webcenter Portal Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h9gj-rqrw-x4fq Server Side Request Forgery in Apache Axis
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 08 May 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Oracle agile Product Lifecycle Management
CPEs cpe:2.3:a:oracle:agile_product_lifecycle_management_framework:9.3.3:*:*:*:*:*:*:* cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*
Vendors & Products Oracle agile Product Lifecycle Management Framework
Oracle agile Product Lifecycle Management

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T17:44:15.943Z

Reserved: 2018-11-14T00:00:00.000Z

Link: CVE-2019-0227

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-05-01T21:29:00.643

Modified: 2025-05-08T18:13:51.353

Link: CVE-2019-0227

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-04-09T00:00:00Z

Links: CVE-2019-0227 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses