← Vulnerability feed

Vulnerability record · CVE-2019-0227 · published 1 May 2019

CVE-2019-0227: Apache Axis 1.4 SSRF via AdminService (expired domain)

Apache · Axis

Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote resource from an attacker-controlled or expired domain, which the referenced research shows can lead to remote code execution. Because Axis 1.4 is embedded in many Oracle and other enterprise products, the exposure is broad and long-lived.

7.5 CVSS 3.1 High EPSS 92% · top 0.2% CWE-918 · Server-side request forgery (SSRF)
7.5CVSS 3.1 base score, v2 5.4
92%EPSS exploitation probability, 30 days
NoNot in CISA KEV
37Affected product versions listed by NVD
26References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue.

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityHigh EPSS and public exploit material combined with unauthenticated adjacent-network reachability and RCE potential make this a serious risk despite the absence of KEV listing.

What it is

Apache Axis 1.4, last released in 2006, contains a server-side request forgery flaw in its AdminService. The service can be induced to fetch a remote resource from an attacker-controlled or expired domain, which the referenced research shows can lead to remote code execution. Because Axis 1.4 is embedded in many Oracle and other enterprise products, the exposure is broad and long-lived.

Impact

An attacker can make the server issue requests to internal or external systems on their behalf, and per the linked research this can escalate to remote code execution on the host. That gives an attacker a foothold inside the network from a single reachable service.

Attack surface

Reached over the network via the Axis AdminService endpoint; the CVSS vector (AV:A) indicates the attacker must be on an adjacent network segment rather than the open internet. No authentication (PR:N) and no user interaction (UI:N) are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.9194, 99.8th percentile) and a third-party reference is tagged Exploit, indicating public exploit material exists. No ransomware group is documented as using it.

What to do

  • Patch or upgrade: move off Axis 1.4 to Axis2 1.7.9 or later, or apply the vendor patch from the Oracle CPU advisories listed in the references.
  • If Axis 1.4 cannot be removed, disable or block the AdminService endpoint and restrict access to it.
  • Segment and firewall the affected hosts so the Axis service is not reachable from adjacent untrusted networks.
  • Inventory all products embedding Axis 1.4 (Oracle and other listed products) and confirm each is patched or isolated.
  • Monitor outbound requests from Axis hosts to unexpected or expired domains.

Detection

  • Alert on requests to the Axis AdminService endpoint, especially from non-administrative source addresses.
  • Monitor outbound HTTP/S connections from Axis hosts to newly registered or expired domains and to internal RFC1918 addresses.
  • Look for DNS queries or HTTP fetches to domains that have lapsed, matching the expired-domain exploitation pattern.
  • Baseline normal Axis service traffic and flag anomalous request patterns to the admin interface.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

37 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apach
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%
https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/ ExploitThird Party Advisory
https://security.netapp.com/advisory/ntap-20240621-0006/
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
https://lists.apache.org/thread.html/r3a5baf5d76f1f2181be7f54da3deab70d7a38b5660b387583d05a8cd%40%3Cjava-user.axis.apach
https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%
https://rhinosecuritylabs.com/application-security/cve-2019-0227-expired-domain-rce-apache-axis/ ExploitThird Party Advisory
https://security.netapp.com/advisory/ntap-20240621-0006/
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2022.html
https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory

Track CVE-2019-0227 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2016-8735Apache Tomcat JmxRemoteLifecycleListener remote code executionApache Tomcat's JmxRemoteLifecycleListener was not updated to match the Oracle CVE-2016-3427 credential-type fix, leaving a deserialization weakness …KEVEPSS 90%analysed8.8CVE-2024-20953Oracle Agile PLM Export deserialization allows takeoverOracle Agile Product Lifecycle Management 9.3.6 contains a deserialization flaw in the Export component. A low-privileged attacker with network acces…KEVEPSS 3.9%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2024-21287Oracle Agile PLM Framework incorrect authorization exposes dataOracle Agile PLM Framework 9.3.6 contains an incorrect authorization flaw in the Software Development Kit / Process Extension component. An unauthent…KEVEPSS 1.7%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.9CVE-2025-21556Oracle agile product lifecycle management incorrect authorization vulnerabilityVulnerability in the Oracle Agile PLM Framework product of Oracle Supply Chain (component: Agile Integration Services). The supported version that is…EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2019-0227), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.