VYPR
Vendor

Axway

Products
3
CVEs
3
Across products
4
Status
Private

Products

3

Recent CVEs

3
CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2013-70570.030.01Nov 4, 2014Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.
CVE-2012-49910.030.04Dec 13, 2012Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.
CVE-2012-64520.000.00May 27, 2014Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.