Axway Secure Messenger prior to 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote malicious users to enumerate users via a series of requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
axway email firewall - |
||
axway secure messenger 6.3.2 |
||
axway secure messenger |