S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2010-0219 Scanner

Detects 'Default Admin Password' vulnerability in Apache Software Foundation Axis2 affects v. 2.1.3 to 2.1.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2010-0219
10.0
CVSS

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Axis2 is an open-source software developed by the Apache Foundation for the deployment and management of web services. It is a flexible, extensible, and scalable platform that supports both SOAP and RESTful web services. Axis2 provides a wide range of features and components, including message-level security, data binding, and transport/payload optimizations, making it a popular choice for enterprise-level web services.

The CVE-2010-0219 vulnerability is a remote code execution vulnerability that affects the default installation of Apache Axis2. The vulnerability arises from the existence of a default, hardcoded password 'axis2' for the admin account in the software. This makes it possible for remote attackers to access and upload a crafted web service that executes arbitrary code. This vulnerability affects many products that use Axis2, such as SAP BusinessObjects Enterprise XI 3.2 and CA ARCserve D2D r15.

Exploiting this vulnerability can lead to serious consequences as attackers can access sensitive data, compromise the confidentiality, integrity, and availability of the system, and even take complete control of the target system. Exploitation of the vulnerability can result in a wide range of attacks, such as data theft, malware distribution, and system compromise. Hence, it is crucial to patch this vulnerability as soon as possible.

Using a vulnerability scanner such as the s4e.io platform can help users detect and discover vulnerabilities in their digital assets quickly and easily. The platform's pro features provide advanced scanning capabilities, such as vulnerability assessment, exploitability analysis, and remediation advice, enabling users to stay ahead of the latest threats and security issues. In conclusion, it is recommended that users take immediate action to mitigate this vulnerability to ensure the protection and security of their digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Change the default admin password during installation or upon first use
  • Disable the admin account when it is not required
  • Use secure passwords that are difficult to guess
  • Configure firewalls and access controls to limit remote access to the system
  • Keep the software updated with the latest patches and security fixes.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2010-0219 scanner - Default Admin Password vulnerability in Apache Software Foundation Axis2 | S4E