Apache Axis2 xsd local file inclusion

  • Apache Axis2 contains a flaw that may allow a remote attacker to access arbitrary files. A remote attacker could send a specially-crafted URL request using the xsd parameter to specify a malicious file from the local system, which could allow the attacker to obtain sensitive information or execute arbitrary code on the vulnerable Web server.
  • Upgrade to the latest version of Apache Axis2. This issue was fixed in Apache Axis2 version 1.4.1.