CVE-2010-0219

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of...

Basic Information

CVE State
PUBLISHED
Reserved Date
January 06, 2010
Published Date
October 18, 2010
Last Updated
August 07, 2024
Vendor
Apache Software Foundation
Product
Axis2
Description
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
Tags
apache nuclei_scanner metasploit_scanner

CVSS Scores

CVSS v2.0

10.0

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score

Score
93.45% (Percentile: 99.81%) as of 2025-05-21

Exploit Status

Exploited in the Wild
Yes (2025-05-10 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-04-23 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

axis2_deployer

Type: metasploit • Created: Unknown

Metasploit module for CVE-2010-0219

veritas-rt/CVE-2010-0219

Type: github • Created: 2024-07-28 14:10:52 UTC • Stars: 1

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei

  • Detected by Metasploit