CVE-2012-6452
Last modified
CVE-2012-6452 is a vulnerability of currently unknown severity. Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.. EPSS estimates a 1.46% chance of exploitation in the next 30 days.
Description
Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axway | Email Firewall | All versions |
| Axway | Secure Messenger | <= 6.5.0 |
| Axway | Secure Messenger | 6.3.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6452?
How severe is CVE-2012-6452?
How do I fix CVE-2012-6452?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6441An information exposure of confidential information results …
- CVE-2012-6442When an affected product receives a valid CIP message from a…7.5
- CVE-2012-6447Cross-site scripting (XSS) vulnerability in Splunk Web in Sp…
- CVE-2012-6448Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 1…6.1
- CVE-2012-6449The clientconf.html and detailbw.html pages in x3 in cPanel …5.4
- CVE-2012-6451Lorex LNC116 and LNC104 IP Cameras have a Remote Authenticat…9.8
- CVE-2012-6453Cross-site scripting (XSS) vulnerability in the RSS Reader e…
- CVE-2012-6458Multiple cross-site scripting (XSS) vulnerabilities in the S…
- CVE-2012-6459ConnMan 1.3 on Tizen continues to list the bluetooth service…
- CVE-2012-6460Opera before 11.67 and 12.x before 12.02 allows remote attac…
- CVE-2012-6461The X.509 certificate-validation functionality in the https …
- CVE-2012-6462Opera before 12.10 does not properly implement the Cross-Ori…
Are you affected by CVE-2012-6452?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
