Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-10305 Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Fixes

Solution

Both issues have been addressed in the most recent version FTA_9_12_220, released on 31 January 2017. Previously, CVE-2016-9500 was addressed in FTA_9_12_160 released on 29 November 2016.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2024-08-06T02:50:38.579Z

Reserved: 2016-11-21T00:00:00

Link: CVE-2016-9499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-13T20:29:02.003

Modified: 2024-11-21T03:01:20.160

Link: CVE-2016-9499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.