CVE-2012-6452

Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:axway:email_firewall:-:*:*:*:*:*:*:*
cpe:2.3:a:axway:secure_messenger:*:*:*:*:*:*:*:*
cpe:2.3:a:axway:secure_messenger:6.3.2:*:*:*:*:*:*:*

History

21 Nov 2024, 01:46

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html - () http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html -
References () http://www.securityfocus.com/bid/57457 - () http://www.securityfocus.com/bid/57457 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/81388 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/81388 -

Information

Published : 2014-05-27 14:55

Updated : 2024-11-21 01:46


NVD link : CVE-2012-6452

Mitre link : CVE-2012-6452

CVE.ORG link : CVE-2012-6452


JSON object : View

Products Affected

axway

  • email_firewall
  • secure_messenger
CWE
CWE-287

Improper Authentication