CVE-2007-2353
Estado: ModificadaMedia (5)—
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 28%
- Percentil entre todas las CVEs puntuadas: 98
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-200
Referencias
- http://attrition.org/pipermail/vim/2007-April/001562.html
- http://www.osvdb.org/34154
- http://www.securityfocus.com/bid/23687
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34167
- http://attrition.org/pipermail/vim/2007-April/001562.html
- http://www.osvdb.org/34154
- http://www.securityfocus.com/bid/23687
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34167
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-2353",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-04-30T22:19:00.000",
"references": [
{
"url": "http://attrition.org/pipermail/vim/2007-April/001562.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/34154",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/23687",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34167",
"source": "cve@mitre.org"
},
{
"url": "http://attrition.org/pipermail/vim/2007-April/001562.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/34154",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/23687",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34167",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message."
},
{
"lang": "es",
"value": "Apache Axis 1.0 permite a atacantes remotos obtener información confidencial al solicitar un fichero WSDL no existente, lo cual revela la ruta de instalación en el mensaje de excepción resultante."
}
],
"lastModified": "2026-06-16T22:39:25.233",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:axis:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "73757AE0-90E2-4043-BCB3-4E4046966CDB"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "Red Hat ship Axis in a number of products; however the installation path of Axis is fixed and deterministic, so this flaw does not disclose otherwise unknown information. We do not plan on issuing updates to fix this issue.",
"lastModified": "2007-05-10T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}