Overview
The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting and information exposure.
Description
CWE-204: Response Discrepancy Information Exposure - CVE-2016-9499 Accellion FTP server only returns the username in the server response if the a username is invalid. An attacker may use this information to determine valid user accounts and enumerate them. |
Impact
A remote attacker may be able to enumerate user accounts on the Accellion FTP server or may conduct reflected cross-site scripting attacks. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Temporal | 3.4 | E:POC/RL:OF/RC:C |
Environmental | 2.5 | CDP:ND/TD:M/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Ashish Kamble for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2016-9499, CVE-2016-9500 |
Date Public: | 2017-01-31 |
Date First Published: | 2017-02-08 |
Date Last Updated: | 2017-02-08 16:27 UTC |
Document Revision: | 30 |