CVE-2018-8032: Apache Axis
Medium severity, CVSS 6.1. EPSS: 10.6% chance of exploitation in the next 30 days.
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Affected products
- Apache Axis: from 1.0, up to and including 1.4
- Debian Debian Linux: version 9.0 only
- Oracle Agile Engineering Data Management: version 6.2.1.0 only
- Oracle Agile Product Lifecycle Management: version 9.3.3 only
- Oracle Application Testing Suite: version 13.2.0.1 only; version 13.3.0.1 only
- Oracle Big Data Discovery: version 1.6 only
- Oracle Communications Asap Cartridges: version 7.2 only; version 7.3 only
- Oracle Communications Design Studio: version 7.3.4.3.0 only; version 7.3.5.5.0 only; version 7.4.0.4.0 only; version 7.4.1.1.0 only
- Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
- Oracle Communications Network Integrity: version 7.3.5 only; version 7.3.6 only
- Oracle Communications Order And Service Management: version 7.3.0.0.0 only; version 7.4 only
- Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
- Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
- Oracle Endeca Information Discovery Studio: version 3.2.0 only
- Oracle Enterprise Manager Base Platform: version 12.1.0.5 only; version 13.3.0.0 only
- Oracle Enterprise Manager For Fusion Middleware: version 12.1.0.5 only
- Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3, up to and including 7.3.5; from 8.0.0, up to and including 8.0.8
- Oracle Financial Services Compliance Regulatory Reporting: from 8.0.6, up to and including 8.0.8
- Oracle Financial Services Funds Transfer Pricing: from 8.0.2, up to and including 8.0.7
- Oracle Flexcube Core Banking: version 11.7.0 only; version 11.8.0 only; version 11.9.0 only; version 11.10.0 only
- Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
- Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle Internet Directory: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Knowledge: from 8.6.0, up to and including 8.6.3
- and 13 more
Published 2018-08-02. Last modified 2026-06-17.