MEDIUM · 6.1

CVE-2018-8032

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Vulnerability Description

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

CVSS Score

6.1

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
ApacheAxis>= 1.0, <= 1.4
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Product Lifecycle Management9.3.3
OracleApplication Testing Suite13.2.0.1
OracleBig Data Discovery1.6
OracleCommunications Asap Cartridges7.2
OracleCommunications Design Studio7.3.4.3.0
OracleCommunications Element Manager8.0.0
OracleCommunications Network Integrity7.3.5
OracleCommunications Order And Service Management7.3.0.0.0
OracleCommunications Session Report Manager8.0.0
OracleCommunications Session Route Manager8.0.0
OracleEndeca Information Discovery Studio3.2.0
OracleEnterprise Manager Base Platform12.1.0.5
OracleEnterprise Manager For Fusion Middleware12.1.0.5
OracleFinancial Services Analytical Applications Infrastructure>= 7.3.3, <= 7.3.5
OracleFinancial Services Compliance Regulatory Reporting>= 8.0.6, <= 8.0.8
OracleFinancial Services Funds Transfer Pricing>= 8.0.2, <= 8.0.7
OracleFlexcube Core Banking11.7.0
OracleFlexcube Private Banking12.0.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-8032?

CVE-2018-8032 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

How severe is CVE-2018-8032?

CVE-2018-8032 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-8032?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Axis, Oracle Agile Engineering Data Management, Oracle Agile Product Lifecycle Management, Oracle Application Testing Suite, Oracle Big Data Discovery.