CVE-2019-14277
Last modified
CVE-2019-14277 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). EPSS estimates a 7.33% chance of exploitation in the next 30 days.
Description
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axway | Securetransport | 5.2.1 |
| Axway | Securetransport | 5.3.0 |
| Axway | Securetransport | 5.3.1 |
| Axway | Securetransport | 5.3.3 |
| Axway | Securetransport | 5.3.6 |
References
- https://www.exploit-db.com/exploits/47150Exploit, Third Party Advisory, VDB Entry
- https://zero.lol/2019-07-21-axway-securetransport-xml-injection/Exploit, Third Party Advisory, URL Repurposed
- https://www.exploit-db.com/exploits/47150Exploit, Third Party Advisory, VDB Entry
- https://zero.lol/2019-07-21-axway-securetransport-xml-injection/Exploit, Third Party Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14277?
How severe is CVE-2019-14277?
How do I fix CVE-2019-14277?
Are you affected by CVE-2019-14277?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
