cve-2010-0219
CRITICAL CVSS 10.0 opencve
Description
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.
Timeline
- Published
- 2010-10-18 17:00 UTC
- Last Modified
- 2026-06-16
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cve": "CVE-2010-0219",
"epss": {
"score": 0.90851
},
"mitre": {
"cpes": [],
"created": "2010-10-18T16:00:00+00:00",
"description": "Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2010/0xxx/CVE-2010-0219.json",
"references": [
"http://retrogod.altervista.org/9sg_ca_d2d.html",
"http://secunia.com/advisories/41799",
"http://secunia.com/advisories/42763",
"http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf",
"http://www.exploit-db.com/exploits/15869",
"http://www.kb.cert.org/vuls/id/989719",
"http://www.osvdb.org/70233",
"http://www.rapid7.com/security-center/advisories/R7-0037.jsp",
"http://www.securityfocus.com/archive/1/514284/100/0/threaded",
"http://www.securitytracker.com/id?1024929",
"http://www.vupen.com/english/advisories/2010/2673",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/62523",
"https://kb.juniper.net/KB27373",
"https://service.sap.com/sap/support/notes/1432881"
],
"title": null,
"updated": "2024-08-07T00:45:10.633000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:apache:axis2:1.3:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.4:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5.2:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:sap:businessobjects:3.2:*:enterprise_xi:*:*:*:*:*"
],
"created": "2010-10-18T17:00:03.457000+00:00",
"description": "Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.",
"metrics": {
"cvssV2_0": {
"score": 10.0,
"vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"nvd_repo_path": "2010/CVE-2010-0219.json",
"references": [
"http://retrogod.altervista.org/9sg_ca_d2d.html",
"http://secunia.com/advisories/41799",
"http://secunia.com/advisories/42763",
"http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf",
"http://www.exploit-db.com/exploits/15869",
"http://www.kb.cert.org/vuls/id/989719",
"http://www.osvdb.org/70233",
"http://www.rapid7.com/security-center/advisories/R7-0037.jsp",
"http://www.securityfocus.com/archive/1/514284/100/0/threaded",
"http://www.securitytracker.com/id?1024929",
"http://www.vupen.com/english/advisories/2010/2673",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/62523",
"https://kb.juniper.net/KB27373",
"https://service.sap.com/sap/support/notes/1432881"
],
"title": null,
"updated": "2026-06-16T23:15:44.017000+00:00",
"vendors": [
"apache",
"apache$PRODUCT$axis2",
"sap",
"sap$PRODUCT$businessobjects"
],
"weaknesses": [
"CWE-255"
]
},
"opencve": {
"changes": [],
"cpes": {
"data": [
"cpe:2.3:a:apache:axis2:1.3:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.4:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5.2:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.5:*:*:*:*:*:*:*",
"cpe:2.3:a:apache:axis2:1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:sap:businessobjects:3.2:*:enterprise_xi:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2010-10-18T16:00:00+00:00",
"provider": "mitre"
},
"description": {
"data": "Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {
"score": 10.0,
"vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C"
},
"provider": "nvd"
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.90851
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"http://retrogod.altervista.org/9sg_ca_d2d.html",
"http://secunia.com/advisories/41799",
"http://secunia.com/advisories/42763",
"http://spl0it.org/files/talks/source_barcelona10/Hacking%20SAP%20BusinessObjects.pdf",
"http://www.exploit-db.com/exploits/15869",
"http://www.kb.cert.org/vuls/id/989719",
"http://www.osvdb.org/70233",
"http://www.rapid7.com/security-center/advisories/R7-0037.jsp",
"http://www.securityfocus.com/archive/1/514284/100/0/threaded",
"http://www.securitytracker.com/id?1024929",
"http://www.vupen.com/english/advisories/2010/2673",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/62523",
"https://kb.juniper.net/KB27373",
"https://service.sap.com/sap/support/notes/1432881"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2025-04-11T00:51:21.963000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"apache",
"apache$PRODUCT$axis2",
"sap",
"sap$PRODUCT$businessobjects"
],
"providers": [
"nvd"
]
},
"weaknesses": {
"data": [
"CWE-255"
],
"providers": [
"nvd"
]
}
}
}
Enrichment data
Aggregated bundle (all enrichments)