CVE-2019-0227: Apache Axis

High severity, CVSS 7.5. EPSS: 91.9% chance of exploitation in the next 30 days.

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

Affected products

  • Apache Axis: version 1.4 only
  • Oracle Agile Engineering Data Management: version 6.2.1.0 only
  • Oracle Agile Product Lifecycle Management: version 9.3.3 only
  • Oracle Application Testing Suite: version 13.2.0.1 only; version 13.3.0.1 only
  • Oracle Big Data Discovery: version 1.6 only
  • Oracle Communications Asap Cartridges: version 7.2 only; version 7.3 only
  • Oracle Communications Design Studio: version 7.3.4.3.0 only; version 7.3.5.5.0 only; version 7.4.0.4.0 only; version 7.4.1.1.0 only
  • Oracle Communications Element Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Network Integrity: version 7.3.5 only; version 7.3.6 only
  • Oracle Communications Order And Service Management: version 7.3.0.0.0 only; version 7.4 only
  • Oracle Communications Session Report Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Communications Session Route Manager: version 8.0.0 only; version 8.1.0 only; version 8.1.1 only; version 8.2.0 only
  • Oracle Endeca Information Discovery Studio: version 3.2.0 only
  • Oracle Enterprise Manager Base Platform: version 12.1.0.5 only; version 13.3.0.0 only
  • Oracle Enterprise Manager For Fusion Middleware: version 12.1.0.5 only
  • Oracle Financial Services Analytical Applications Infrastructure: from 7.3.3, up to and including 7.3.5; from 8.0.0, up to and including 8.0.8
  • Oracle Financial Services Compliance Regulatory Reporting: from 8.0.6, up to and including 8.0.8
  • Oracle Financial Services Funds Transfer Pricing: from 8.0.2, up to and including 8.0.7
  • Oracle Flexcube Core Banking: version 11.7.0 only; version 11.8.0 only; version 11.9.0 only; version 11.10.0 only
  • Oracle Flexcube Private Banking: version 12.0.0 only; version 12.1.0 only
  • Oracle Hospitality Guest Access: version 4.2.0 only; version 4.2.1 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle Internet Directory: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Knowledge: from 8.6.0, up to and including 8.6.3
  • Oracle PeopleSoft Enterprise Human Capital Management Human Resources: version 7.3.5 only; version 7.3.6 only; version 9.2 only
  • and 12 more

Published 2019-05-01. Last modified 2026-06-17.