Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2018-07-13T20:00:00
Updated: 2024-08-06T02:50:38.579Z
Reserved: 2016-11-21T00:00:00
Link: CVE-2016-9499
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-07-13T20:29:02.003
Modified: 2024-11-21T03:01:20.160
Link: CVE-2016-9499
Redhat
No data.