First published: Fri Jul 13 2018(Updated: )
Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Accellion FTP server | <fta_9_12_220 |
Both issues have been addressed in the most recent version FTA_9_12_220, released on 31 January 2017. Previously, CVE-2016-9500 was addressed in FTA_9_12_160 released on 29 November 2016.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9499 is a vulnerability in Accellion FTP server prior to version FTA_9_12_220 that allows an attacker to determine valid user accounts by analyzing server responses.
The severity of CVE-2016-9499 is medium with a CVSS score of 5.3.
CVE-2016-9499 affects Accellion FTP server prior to version FTA_9_12_220, where it only returns the username in the server response if the username is invalid.
An attacker can exploit CVE-2016-9499 by analyzing the server responses to determine valid user accounts.
To fix CVE-2016-9499, update Accellion FTP server to version FTA_9_12_220 or newer.