logo

Database

Technical information leak In org.apache.axis:axis

Description

Apache Axis allows Exposure of Sensitive Information to an Unauthorized Actor Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions