Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
2010-10-18T17:00:03.457
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | axis2 | 1.3 | Yes |
Application | apache | axis2 | 1.4 | Yes |
Application | apache | axis2 | 1.4.1 | Yes |
Application | apache | axis2 | 1.5 | Yes |
Application | apache | axis2 | 1.5.1 | Yes |
Application | apache | axis2 | 1.5.2 | Yes |
Application | apache | axis2 | 1.6 | Yes |
Application | sap | businessobjects | 3.2 | Yes |