{"api_version":"1","generated_at":"2026-07-23T06:11:27+00:00","cve":"CVE-2012-6452","urls":{"html":"https://cve.report/CVE-2012-6452","api":"https://cve.report/api/cve/CVE-2012-6452.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-6452","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-6452"},"summary":{"title":"CVE-2012-6452","description":"Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-05-27 14:55:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81388","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81388","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/57457","name":"http://www.securityfocus.com/bid/57457","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Axway Secure Messenger CVE-2012-6452 Remote Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html","name":"http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-6452","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-6452","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"6452","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"axway","cpe5":"email_firewall","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6452","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"axway","cpe5":"secure_messenger","cpe6":"6.3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"6452","vulnerable":"1","versionEndIncluding":"6.5.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"axway","cpe5":"secure_messenger","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:28:39.799Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20130117 CVE-2012-6452 Axway Secure Messenger Username Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html"},{"name":"57457","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/57457"},{"name":"axway-secure-info-disc(81388)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81388"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2013-01-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20130117 CVE-2012-6452 Axway Secure Messenger Username Disclosure","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html"},{"name":"57457","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/57457"},{"name":"axway-secure-info-disc(81388)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81388"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-6452","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20130117 CVE-2012-6452 Axway Secure Messenger Username Disclosure","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2013-01/0076.html"},{"name":"57457","refsource":"BID","url":"http://www.securityfocus.com/bid/57457"},{"name":"axway-secure-info-disc(81388)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/81388"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-6452","datePublished":"2014-05-27T15:00:00.000Z","dateReserved":"2012-12-28T00:00:00.000Z","dateUpdated":"2024-08-06T21:28:39.799Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-05-27 14:55:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:axway:email_firewall:-:*:*:*:*:*:*:*","matchCriteriaId":"9ECB570C-C0AB-4BE9-B252-3999C76B5820"},{"vulnerable":true,"criteria":"cpe:2.3:a:axway:secure_messenger:*:*:*:*:*:*:*:*","versionEndIncluding":"6.5.0","matchCriteriaId":"B166EECB-E2A4-4E39-BCDB-33175A8C44F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:axway:secure_messenger:6.3.2:*:*:*:*:*:*:*","matchCriteriaId":"B07085D5-3101-4715-A64C-5465C5D2B9AD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"6452","Ordinal":"1","Title":"CVE-2012-6452","CVE":"CVE-2012-6452","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"6452","Ordinal":"1","NoteData":"Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, which allows remote attackers to enumerate users via a series of requests.","Type":"Description","Title":"CVE-2012-6452"},{"CveYear":"2012","CveId":"6452","Ordinal":"2","NoteData":"2014-05-27","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"6452","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}