By default, Apache Axis2 deploys with a default password. The admin account has a password of axis2 which is publicly known and documented. This allows a remote attacker to execute arbitrary code by uploading a crafted web service.
Classification
Location:
Remote / Network Access
Attack Type:
Authentication Management
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Patch / RCS
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, SAP has released a patch to address this vulnerability.