VYPR

Securetransport

by Axway

CVEs (2)

  • CVE-2013-7057Nov 4, 2014
    risk 0.03cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.

  • CVE-2012-4991Dec 13, 2012
    risk 0.03cvss epss 0.04

    Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.