Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-10305 | Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them. |
Fixes
Solution
Both issues have been addressed in the most recent version FTA_9_12_220, released on 31 January 2017. Previously, CVE-2016-9500 was addressed in FTA_9_12_160 released on 29 November 2016.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2024-08-06T02:50:38.579Z
Reserved: 2016-11-21T00:00:00
Link: CVE-2016-9499
No data.
Status : Modified
Published: 2018-07-13T20:29:02.003
Modified: 2024-11-21T03:01:20.160
Link: CVE-2016-9499
No data.
OpenCVE Enrichment
No data.
EUVD