← Vulnerability feed

Vulnerability record · CVE-2010-0219 · published 18 October 2010

CVE-2010-0219: Apache Axis2 default admin password enables remote code execution

Apache · Axis2

Apache Axis2, as bundled in products such as SAP BusinessObjects Enterprise XI 3.2 and CA ARCserve D2D r15, ships with a default password of 'axis2' for its admin account. An attacker who reaches the admin interface can authenticate with these known credentials and upload a crafted web service, turning a configuration weakness into remote code execution.

10.0 CVSS 2.0 High EPSS 91% · top 0.2% CWE-255 · CWE-255
10.0CVSS 2.0 base score
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityA default administrative credential on a network-reachable service with a CVSS 2.0 score of 10 and public exploit references allows unauthenticated attackers to achieve remote code execution.

What it is

Apache Axis2, as bundled in products such as SAP BusinessObjects Enterprise XI 3.2 and CA ARCserve D2D r15, ships with a default password of 'axis2' for its admin account. An attacker who reaches the admin interface can authenticate with these known credentials and upload a crafted web service, turning a configuration weakness into remote code execution.

Impact

An attacker gains administrative control of the Axis2 service and can execute arbitrary code on the host by deploying a malicious web service. This typically yields full compromise of the application server and any data or credentials it can reach.

Attack surface

The flaw is reachable over the network through the exposed Axis2 administrative interface (AV:N/AC:L/Au:N), so no prior authentication is required because the default credentials are the authentication. No user interaction is described in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.90851, 99.8th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. The record does not state whether exploitation has been observed in the wild.

What to do

  • Apply the vendor patch referenced in the SAP support note (service.sap.com/sap/support/notes/1432881) and any Axis2 updates for affected products.
  • Immediately change the default 'axis2' admin password on every exposed Axis2 instance and remove or disable the admin application where it is not needed.
  • Restrict network access to the Axis2 admin interface to trusted management hosts only.
  • Audit bundled Axis2 deployments in SAP BusinessObjects and CA ARCserve D2D for the same default credential.
  • Monitor for unauthorized web service deployments and treat any unexpected .aar upload as a compromise indicator.

Detection

  • Search web and application logs for authentication to the Axis2 admin console using the account 'axis2' or the password 'axis2'.
  • Alert on uploads of .aar files or new web service deployments outside change windows.
  • Baseline and monitor outbound connections from the Axis2 host for signs of post-exploitation activity.
  • Inventory internet- or network-exposed Axis2 admin endpoints and verify the default password has been changed.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0219 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-7730Sap businessobjects memory buffer overflow vulnerabilitySAP BusinessObjects BI Platform 4.1, BusinessObjects Edge 4.0, and BusinessObjects XI (BOXI) 3.1 R3 allow remote attackers to cause a denial of servi…EPSS 3.6%10.0CVE-2014-9387Sap businessobjects permissions and access controls vulnerabilitySAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…EPSS 4.6%9.8CVE-2019-0259Sap businessobjects unrestricted file upload vulnerabilitySAP BusinessObjects, versions 4.2 and 4.3, (Visual Difference) allows an attacker to upload any file (including script files) without proper file for…EPSS 2.0%9.0CVE-2010-3983Sap businessobjects permissions and access controls vulnerabilityCmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and…EPSS 1.7%7.8CVE-2022-28214Sap businessobjects cleartext storage of sensitive data vulnerabilityDuring an update of SAP BusinessObjects Enterprise, Central Management Server (CMS) - versions 420, 430, authentication credentials are being exposed…EPSS 0.17%7.6CVE-2019-0287Sap businessobjects vulnerabilityUnder certain conditions SAP BusinessObjects Business Intelligence platform (Central Management Server), versions 4.2 and 4.3, allows an attacker to …EPSS 1.7%7.5CVE-2010-1632Apache axis2 improper input validation vulnerabilityApache Axis2 before 1.5.2, as used in IBM WebSphere Application Server (WAS) 7.0 through 7.0.0.12, IBM Feature Pack for Web Services 6.1.0.9 through …EPSS 22%7.3CVE-2018-2408Sap businessobjects vulnerabilityImproper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI Launchpad/Fiorified BI Launchpad. In case of password ch…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2010-0219), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.