vendor:
Secure Transport
by:
Sebastian Perez
8,5
CVSS
HIGH
Path Traversal
22
CWE
Product Name: Secure Transport
Affected Version From: 5.1 SP2
Affected Version To: 5.1 SP2
Patch Exists: YES
Related CWE: CVE-2012-4991
CPE: a:axway:secure_transport
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Microsoft Windows
2012
Secure Transport Path Traversal Vulnerability
A path traversal vulnerability was identified in SecureTransport versions 5.1 SP2 and earlier on the Microsoft Windows platform that could allow tampering and information disclosure. This vulnerability allows remote attackers to access other user's directories, and also to read, download, delete and upload arbitrary files. This can be performed using a encoded backslash characters (%5c) in the path.
Mitigation:
For 4.9.2 sp2: https://support.axway.com/en/downloads/download-details/id/35283 For 5.1 sp2: https://support.axway.com/en/downloads/download-details/id/35957