CVE-2012-4991 | Date: (C)2012-12-13 (M)2023-12-22 |
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list directories, via a ..%5C (encoded dot dot backslash) in a URI.
CVSS Score and Metrics +CVSS Score and Metrics -CVSS V2 Severity: |
CVSS Score : 8.5 |
Exploit Score: 8.0 |
Impact Score: 9.2 |
|
CVSS V2 Metrics: |
Access Vector: NETWORK |
Access Complexity: LOW |
Authentication: SINGLE |
Confidentiality: COMPLETE |
Integrity: COMPLETE |
Availability: NONE |
| |