Vulnerabilities (CVE)

Filtered by vendor Axway Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-7057 1 Axway 1 Securetransport 2017-08-29 6.8 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.
CVE-2012-6452 1 Axway 2 Email Firewall, Secure Messenger 2017-08-29 5.0 MEDIUM N/A
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
CVE-2012-4991 1 Axway 1 Securetransport 2012-12-13 8.5 HIGH N/A
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.