CVE-2018-8032

Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
apacheaxis
1.0 ≤
𝑥
≤ 1.4
oracleagile_engineering_data_management
6.2.1.0
oracleagile_product_lifecycle_management
9.3.3
oracleapplication_testing_suite
13.2.0.1
oracleapplication_testing_suite
13.3.0.1
oraclebig_data_discovery
1.6
oraclecommunications_asap_cartridges
7.2
oraclecommunications_asap_cartridges
7.3
oraclecommunications_design_studio
7.3.4.3.0
oraclecommunications_design_studio
7.3.5.5.0
oraclecommunications_design_studio
7.4.0.4.0
oraclecommunications_design_studio
7.4.1.1.0
oraclecommunications_element_manager
8.0.0
oraclecommunications_element_manager
8.1.0
oraclecommunications_element_manager
8.1.1
oraclecommunications_element_manager
8.2.0
oraclecommunications_network_integrity
7.3.5
oraclecommunications_network_integrity
7.3.6
oraclecommunications_order_and_service_management
7.3.0.0.0
oraclecommunications_order_and_service_management
7.4
oraclecommunications_session_report_manager
8.0.0
oraclecommunications_session_report_manager
8.1.0
oraclecommunications_session_report_manager
8.1.1
oraclecommunications_session_report_manager
8.2.0
oraclecommunications_session_route_manager
8.0.0
oraclecommunications_session_route_manager
8.1.0
oraclecommunications_session_route_manager
8.1.1
oraclecommunications_session_route_manager
8.2.0
oracleendeca_information_discovery_studio
3.2.0
oracleenterprise_manager_base_platform
12.1.0.5
oracleenterprise_manager_base_platform
13.3.0.0
oracleenterprise_manager_for_fusion_middleware
12.1.0.5
oraclefinancial_services_analytical_applications_infrastructure
7.3.3 ≤
𝑥
≤ 7.3.5
oraclefinancial_services_analytical_applications_infrastructure
8.0.0 ≤
𝑥
≤ 8.0.8
oraclefinancial_services_compliance_regulatory_reporting
8.0.6 ≤
𝑥
≤ 8.0.8
oraclefinancial_services_funds_transfer_pricing
8.0.2 ≤
𝑥
≤ 8.0.7
oracleflexcube_core_banking
11.7.0
oracleflexcube_core_banking
11.8.0
oracleflexcube_core_banking
11.9.0
oracleflexcube_core_banking
11.10.0
oracleflexcube_private_banking
12.0.0
oracleflexcube_private_banking
12.1.0
oraclehospitality_guest_access
4.2.0
oraclehospitality_guest_access
4.2.1
oracleinstantis_enterprisetrack
17.1
oracleinstantis_enterprisetrack
17.2
oracleinstantis_enterprisetrack
17.3
oracleinternet_directory
12.2.1.3.0
oracleinternet_directory
12.2.1.4.0
oracleknowledge
8.6.0 ≤
𝑥
≤ 8.6.3
oraclepeoplesoft_enterprise_human_capital_management_human_resources
9.2
oraclepeoplesoft_enterprise_peopletools
8.56
oraclepeoplesoft_enterprise_peopletools
8.57
oraclepeoplesoft_enterprise_peopletools
8.58
oraclepolicy_automation_connector_for_siebel
10.4.6
oracleprimavera_gateway
16.2.11
oracleprimavera_gateway
17.12.6
oracleprimavera_unifier
17.7 ≤
𝑥
≤ 17.12
oracleprimavera_unifier
16.1
oracleprimavera_unifier
16.2
oracleprimavera_unifier
18.8
oracleprimavera_unifier
19.12
oraclerapid_planning
12.1
oraclerapid_planning
12.2
oraclereal-time_decision_server
3.2.1.0
oracleretail_order_broker
15.0
oracleretail_order_broker
16.0
oracleretail_order_broker
18.0
oracleretail_xstore_point_of_service
7.1
oraclesecure_global_desktop
5.4
oraclesecure_global_desktop
5.5
oraclesiebel_ui_framework
𝑥
≤ 21.0
oracletuxedo
12.1.1.0.0
oracletuxedo
12.1.3
oraclewebcenter_portal
12.2.1.3.0
debiandebian_linux
9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
axis
bullseye
1.4-28+deb11u1
fixed
jessie
no-dsa
bookworm
1.4-28+deb12u1
fixed
sid
1.4-29
fixed
trixie
1.4-29
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
axis
noble
not-affected
mantic
not-affected
lunar
not-affected
kinetic
not-affected
jammy
not-affected
impish
not-affected
hirsute
not-affected
groovy
not-affected
focal
not-affected
eoan
not-affected
disco
not-affected
cosmic
ignored
bionic
needs-triage
xenial
needs-triage
trusty
dne
References