MEDIUM🇵🇱 Wersja polska

CVE-2012-6452

CVSS 5.0v2.0pub. 2014-05-27upd. 2026-05-06

Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.

CVSS Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
  • Axway Email Firewall

    APP
    Axway
    all versions
  • Axway Secure Messenger

    APP
    Axway
    6.3.2≤ 6.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
FirewallAuth Bypass
CWE
References

Related vulnerabilities

CVE-2019-14277CRITICAL9.8PL ✓same vendor

Axway SecureTransport — nieuwierzytelniona podatność XXE/XML Injection w API

CVE-2015-5606HIGH7.5same vendor

Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service...

CVE-2019-6500HIGH7.5same vendor

In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by ...

CVE-2012-4991HIGH8.5same vendor

Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authent...

CVE-2013-7057MEDIUM6.8same vendor

Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote att...