CVE-2012-4991 EXPLOIT
8.5
HIGH · CVSS 2.0 · EPSS 4.6% (pctl 91)
Patch early
A public exploit exists.
Description
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.
Scoring
| CVSS | 8.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
| EPSS | 4.55% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-12-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| axway | securetransport |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Axway Secure Transport 5.1 SP2 - Directory Traversal | 2012-12-12 |
→ the Explorer · watch your stack · NVD