CVE-2012-6452
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0035 (0.3%)
Percentile: 57.3%
EPSS: 2026-05-06
Affects
axway:email_firewallaxway:secure_messengerTechnical description
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
Published: 5/27/2014, 2:55:03 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html
- http://www.securityfocus.com/bid/57457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81388
- http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html
- http://www.securityfocus.com/bid/57457
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81388