CVE-2010-2103

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the modules parameter.  NOTE: some of these details are obtained from third party information.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 95%
VendorProductVersion
apacheaxis2
1.4.1
apacheaxis2
1.5.1
apacheaxis2
1.4.1
apacheaxis2
1.5.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
axis
bullseye
1.4-28+deb11u1
fixed
bookworm
1.4-28+deb12u1
fixed
sid
1.4-29
fixed
trixie
1.4-29
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
axis
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
ignored
maverick
ignored
lucid
not-affected
karmic
ignored
jaunty
ignored
hardy
ignored
dapper
dne