** UNSUPPORTED WHEN ASSIGNED ** Improper Input Validation vulnerability in Apache Axis allowed users with access to the admin service to perform possible SSRF This issue affects Apache Axis: through 1.3.
As Axis 1 has been EOL we recommend you migrate to a different SOAP engine, such as Apache Axis 2/Java. Alternatively you could use a build of Axis with the patch from https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06 applied. The Apache Axis project does not expect to create an Axis 1.x release fixing this problem, though contributors that would like to work towards this are welcome.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/51xxx/CVE-2023-51441.json",
"cna_assigner": "apache",
"cwe_ids": [
"CWE-918"
]
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.3"
}
],
"cpe": "cpe:2.3:a:apache:axis:*:*:*:*:*:*:*:*"
}"2026-07-22T02:50:34Z"
[
{
"signature_version": "v1",
"target": {
"file": "axis-rt-core/src/main/java/org/apache/axis/client/ServiceFactory.java",
"function": "getService"
},
"id": "CVE-2023-51441-5b7d340c",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "161160313230098078489763587029481210102",
"length": 1076.0
},
"source": "https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06"
},
{
"signature_version": "v1",
"target": {
"file": "axis-rt-core/src/main/java/org/apache/axis/client/ServiceFactory.java"
},
"id": "CVE-2023-51441-a3368dc0",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"26434549728962744336481821101478524324",
"216585420375829358243775026091412444872",
"146181473248716451035113682811798281950",
"201618453429055515631509454256710710217",
"248039331516895908668315728166914382666",
"37921761454406861802539796240313872899",
"240875880600203567366555604319701489762",
"313840964701241501718335840874855727223",
"139643275528754068793148914314370692638",
"312370538263353700415937499163480784001",
"47752315233520453246327495403743032907",
"12028879795223648933526132773869190459",
"313551125448531415526556704412024824408"
]
},
"source": "https://github.com/apache/axis-axis1-java/commit/685c309febc64aa393b2d64a05f90e7eb9f73e06"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-51441.json"