Tracker / CVE-2018-8032
CVE-2018-8032
Medium 6.1
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
Affected products and versions
| apache | axis · 1.0 → 1.4 |
|---|---|
| debian | debian_linux |
| oracle | agile_engineering_data_management |
| oracle | agile_product_lifecycle_management |
| oracle | application_testing_suite |
| oracle | big_data_discovery |
| oracle | communications_asap_cartridges |
| oracle | communications_design_studio |
| oracle | communications_element_manager |
| oracle | communications_network_integrity |
| oracle | communications_order_and_service_management |
| oracle | communications_session_report_manager |
| oracle | communications_session_route_manager |
| oracle | endeca_information_discovery_studio |
| oracle | enterprise_manager_base_platform |
| oracle | enterprise_manager_for_fusion_middleware |
| oracle | financial_services_analytical_applications_infrastructure · 7.3.3 → 7.3.5 |
| oracle | financial_services_analytical_applications_infrastructure · 8.0.0 → 8.0.8 |
| oracle | financial_services_compliance_regulatory_reporting · 8.0.6 → 8.0.8 |
| oracle | financial_services_funds_transfer_pricing · 8.0.2 → 8.0.7 |
| oracle | flexcube_core_banking |
| oracle | flexcube_private_banking |
| oracle | hospitality_guest_access |
| oracle | instantis_enterprisetrack |
| oracle | internet_directory |
| oracle | knowledge · 8.6.0 → 8.6.3 |
| oracle | peoplesoft_enterprise_human_capital_management_human_resources |
| oracle | peoplesoft_enterprise_peopletools |
| oracle | policy_automation_connector_for_siebel |
| oracle | primavera_gateway |
| oracle | primavera_unifier |
| oracle | primavera_unifier · 17.7 → 17.12 |
| oracle | rapid_planning |
| oracle | real-time_decision_server |
| oracle | retail_order_broker |
| oracle | retail_xstore_point_of_service |
| oracle | secure_global_desktop |
| oracle | siebel_ui_framework · … → 21.0 |
| oracle | tuxedo |
| oracle | webcenter_portal |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.