Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published: 2018-07-13T20:00:00

Updated: 2024-08-06T02:50:38.579Z

Reserved: 2016-11-21T00:00:00

Link: CVE-2016-9499

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-07-13T20:29:02.003

Modified: 2019-10-09T23:20:33.133

Link: CVE-2016-9499

cve-icon Redhat

No data.