peter bassill · operator
$ cve CVE-2012-4991 JSON

CVE-2012-4991 EXPLOIT

8.5
HIGH · CVSS 2.0 · EPSS 4.6% (pctl 91)

Patch early

A public exploit exists.

Description

Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.

Scoring

CVSS8.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
EPSS4.55% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-22
On CISA KEVno
Public exploityes
Published2012-12-13
Last modified2026-06-16

Affected (1)

VendorProduct
axwaysecuretransport

Public exploits

SourceTitleDate
exploit-dbAxway Secure Transport 5.1 SP2 - Directory Traversal2012-12-12

References

→ the Explorer  ·  watch your stack  ·  NVD