Apache SOAP是美国阿帕奇(Apache)基金会的用作客户端库来调用其他地方可用的 SOAP 服务,也可以用作服务器端工具来实现 SOAP 可访问服务。 Apache SOAP存在安全漏洞,该漏洞源于 RPCRouterServlet 中的 XML 外部实体引用限制不当,攻击者利用该漏洞可以过 HTTP 读取任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache SOAP | 2.2 ~ Apache SOAP* | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-38398 | Server-Side Request Forgery Information Disclosure Vulnerability | |
| CVE-2022-38648 | PDFTranscoder does not block external resources | |
| CVE-2022-40146 | Jar url should be blocked by DefaultScriptSecurity |
No comments yet