CVE-2016-9499: The Accellion FTP server prior to version FTA_9_12_220 is vulnerable to cross-site scripting.
Accellion FTP server prior to version FTA912220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2016-9499?
CVE-2016-9499 is a vulnerability in Accellion FTP server prior to version FTA_9_12_220 that allows an attacker to determine valid user accounts by analyzing server responses.
What is the severity of CVE-2016-9499?
The severity of CVE-2016-9499 is medium with a CVSS score of 5.3.
How does CVE-2016-9499 affect Accellion FTP server?
CVE-2016-9499 affects Accellion FTP server prior to version FTA_9_12_220, where it only returns the username in the server response if the username is invalid.
How can an attacker exploit CVE-2016-9499?
An attacker can exploit CVE-2016-9499 by analyzing the server responses to determine valid user accounts.
How can I fix CVE-2016-9499?
To fix CVE-2016-9499, update Accellion FTP server to version FTA_9_12_220 or newer.