CVE-2012-6452

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
27/05/2014
Last modified:
12/04/2025

Description

Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:axway:email_firewall:-:*:*:*:*:*:*:*
cpe:2.3:a:axway:secure_messenger:*:*:*:*:*:*:*:* 6.5.0 (including)
cpe:2.3:a:axway:secure_messenger:6.3.2:*:*:*:*:*:*:*