CVE-2026-9177
- EPSS 0.29%
- Veröffentlicht 29.07.2026 13:46:06
- Zuletzt bearbeitet 30.07.2026 20:27:10
A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This flaw allows an attacker with admin privileges to inject arbitrary Java code ...
CVE-2019-14277
- EPSS 7.33%
- Veröffentlicht 26.07.2019 04:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:21
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functionality via the REST API. This vulnerability can lead to local file di...
CVE-2013-7057
- EPSS 1.43%
- Veröffentlicht 04.11.2014 15:55:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.
CVE-2012-4991
- EPSS 4.55%
- Veröffentlicht 13.12.2012 11:53:33
- Zuletzt bearbeitet 16.06.2026 23:46:01
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.