CVE-2018-8032: Apache Axis

Medium severity, CVSS 6.1. EPSS: 10.6% chance of exploitation in the next 30 days.

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

Affected products

  • Apache Axis: from 1.0, up to and including 1.4
  • Debian Debian Linux: version 9.0 only
  • Oracle Agile Engineering Data Management: version 6.2.1.0 only
  • Oracle Agile Product Lifecycle Management: version 9.3.3 only
  • Oracle Application Testing Suite: version 13.2.0.1 only; version 13.3.0.1 only
  • Oracle Big Data Discovery: version 1.6 only
  • Oracle Communications Asap Cartridges: version 7.2 only; version 7.3 only
  • Oracle Communications Design Studio: version 7.3.4.3.0 only; version 7.3.5.5.0 only; version 7.4.0.4.0 only; version 7.4.1.1.0 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Network Integrity: version 7.3.5 only; version 7.3.6 only
  • Oracle Communications Order And Service Management: version 7.3.0.0.0 only; version 7.4 only
  • Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Endeca Information Discovery Studio: version 3.2.0 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5 only; version 13.3.0.0 only
  • Oracle Enterprise Manager For Fusion Middleware: version 12.1.0.5 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3, up to and including 7.3.5; from 8.0.0, up to and including 8.0.8
  • Oracle Financial Services Compliance Regulatory Reporting: from 8.0.6, up to and including 8.0.8
  • Oracle Financial Services Funds Transfer Pricing: from 8.0.2, up to and including 8.0.7
  • Oracle Flexcube Core Banking: version 11.7.0 only; version 11.8.0 only; version 11.9.0 only; version 11.10.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Internet Directory: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Knowledge: from 8.6.0, up to and including 8.6.3
  • and 13 more

Published 2018-08-02. Last modified 2026-06-17.