CVE-2010-0219

High PUBLISHED

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of...

Vendor: Apache Product: Axis2

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High EPSS 89.9%

At a Glance

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

nuclei_scanner metasploit apache
CVE Published
Oct 18, 2010
Exploitation Reported
Apr 23, 2025
CVSS
10.0 High
EPSS
89.9%
Remote Low complexity Unauthenticated

CVE References

  • 41799 secunia.com · Third-Party Advisory http://secunia.com/advisories/41799
  • 42763 secunia.com · Third-Party Advisory http://secunia.com/advisories/42763
  • VU#989719 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/989719
  • 15869 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15869
  • 70233 osvdb.org · VDB Entry http://www.osvdb.org/70233
Show 9 more references