CVE-2019-14277
Last modified
CVE-2019-14277 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). EPSS estimates a 7.33% chance of exploitation in the next 30 days.
Description
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file disclosure, DoS, or URI invocation attacks (i.e., SSRF with resultant remote code execution). NOTE: The vendor disputes this issues as not being a vulnerability because “All attacks that use external entities are blocked (no external DTD or file inclusions, no SSRF). The impact on confidentiality, integrity and availability is not proved on any version.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Axway | Securetransport | 5.2.1 |
| Axway | Securetransport | 5.3.0 |
| Axway | Securetransport | 5.3.1 |
| Axway | Securetransport | 5.3.3 |
| Axway | Securetransport | 5.3.6 |
References
- https://www.exploit-db.com/exploits/47150Exploit, Third Party Advisory, VDB Entry
- https://zero.lol/2019-07-21-axway-securetransport-xml-injection/Exploit, Third Party Advisory, URL Repurposed
- https://www.exploit-db.com/exploits/47150Exploit, Third Party Advisory, VDB Entry
- https://zero.lol/2019-07-21-axway-securetransport-xml-injection/Exploit, Third Party Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14277?
How severe is CVE-2019-14277?
How do I fix CVE-2019-14277?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-14271In Docker 19.03.x before 19.03.1 linked against the GNU C Li…9.8
- CVE-2019-14272In SilverStripe asset-admin 4.0, there is XSS in file titles…5.4
- CVE-2019-14273In SilverStripe assets 4.0, there is broken access control o…5.3
- CVE-2019-14274MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() …5.5
- CVE-2019-14275Xfig fig2dev 3.2.7a has a stack-based buffer overflow in the…5.5
- CVE-2019-14276WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request bod…6.5
- CVE-2019-14278In Knowage through 6.1.1, an unauthenticated user can enumer…
- CVE-2019-1428A remote code execution vulnerability exists in the way that…7.5
- CVE-2019-14280In some circumstances, Craft 2 before 2.7.10 and 3 before 3.…
- CVE-2019-14281The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.…
- CVE-2019-14282The simple_captcha2 gem 0.2.3 for Ruby, as distributed on Ru…
- CVE-2019-14283In the Linux kernel before 5.2.3, set_geometry in drivers/bl…
Are you affected by CVE-2019-14277?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
