CVE-2010-0219

High PUBLISHED

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of...

Apache · Axis2

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High

At a Glance

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

nuclei_scanner metasploit apache
CVE Published
Oct 18, 2010
Exploitation Reported
Apr 23, 2025
CVSS
10.0 High
EPSS
Remote Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • 41799 secunia.com · Third-Party Advisory http://secunia.com/advisories/41799
  • 42763 secunia.com · Third-Party Advisory http://secunia.com/advisories/42763
  • VU#989719 kb.cert.org · Third-Party Advisory http://www.kb.cert.org/vuls/id/989719
  • 15869 exploit-db.com · Exploit http://www.exploit-db.com/exploits/15869
  • 70233 osvdb.org · VDB Entry http://www.osvdb.org/70233
Show 9 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.