Vulnerability record · CVE-2019-0227 · published 1 May 2019
CVE-2019-0227: Apache Axis 1.4 SSRF via AdminService (expired domain)
Apache · Axis
Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote resource from an attacker-controlled or expired domain, which the referenced research shows can lead to remote code execution. Because Axis 1.4 is embedded in many Oracle and other enterprise products, the exposure is broad and long-lived.
Description
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityHigh EPSS and public exploit material combined with unauthenticated adjacent-network reachability and RCE potential make this a serious risk despite the absence of KEV listing.
What it is
Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote resource from an attacker-controlled or expired domain, which the referenced research shows can lead to remote code execution. Because Axis 1.4 is embedded in many Oracle and other enterprise products, the exposure is broad and long-lived.
Impact
An attacker can make the server issue requests to internal or external systems on their behalf, and per the linked research this can escalate to remote code execution on the host. That gives an attacker a foothold inside the network from a single reachable service.
Attack surface
Reached over the network via the Axis AdminService endpoint; the CVSS vector (AV:A) indicates the attacker must be on an adjacent network segment rather than the open internet. No authentication (PR:N) and no user interaction (UI:N) are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.9194, 99.8th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.
What to do
- Patch or upgrade: move off Axis 1.4 to Axis2 1.7.9 or later, or apply the vendor patch from the Oracle CPU advisories listed in the references.
- If Axis 1.4 cannot be removed, disable or block the AdminService endpoint and restrict access to it.
- Segment and firewall the affected hosts so the Axis service is not reachable from adjacent untrusted networks.
- Inventory all products embedding Axis 1.4 (Oracle and other listed products) and confirm each is patched or isolated.
- Monitor outbound requests from Axis hosts to unexpected or expired domains.
Detection
- Alert on requests to the Axis AdminService endpoint, especially from non-administrative source addresses.
- Monitor outbound HTTP/S connections from Axis hosts to newly registered or expired domains and to internal RFC1918 addresses.
- Look for DNS queries or HTTP fetches to domains that have lapsed, matching the expired-domain exploitation pattern.
- Baseline normal Axis service traffic and flag anomalous request patterns to the admin interface.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
37 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0227 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0227), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.