Axway's vulnerability profile concentrates in a focused portfolio of secure data-exchange and messaging infrastructure products such as SecureTransport, File Transfer Direct, and its XML gateway platform, which serve critical roles in regulated enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity and a strong tendency to acquire public exploit code; the exposure recurs through authentication, input validation, and path-traversal weakness classes that are characteristic of gateway and protocol-handling appliances. Defenders should prioritize monitoring this vendor's updates for internet-exposed data-transfer and API-gateway instances; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Axway over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4991HIGH Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated users to (1) read, (2) delete, or (3) create files, or (4) list | Dec 13, 2012 | 8.5 | 36 | NO | YES |
CVE-2019-14277CRITICAL Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injection (and XXE) in the resetPassword functi | Jul 26, 2019 | 9.8 | 34 | NO | NO |
CVE-2013-7057MEDIUM Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests | Nov 4, 2014 | 6.8 | 32 | NO | YES |
CVE-2015-5606HIGH Vordel XML Gateway (acquired by Axway) version 7.2.2 could allow remote attackers to cause a denial of service via a specially crafted request. | Apr 3, 2019 | 7.5 | 26 | NO | NO |
CVE-2019-6500HIGH In Axway File Transfer Direct 2.7.1, an unauthenticated Directory Traversal vulnerability can be exploited by issuing a specially crafted HTTP GET request with %2e instead of '.' c | Jan 21, 2019 | 7.5 | 26 | NO | NO |
CVE-2012-6452MEDIUM Axway Secure Messenger before 6.5 Updated Release 7, as used in Axway Email Firewall, provides different responses to authentication requests depending on whether the user exists, | May 27, 2014 | 5.0 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Axway.
Media articles that mention a CVE ID that affects a product developed by Axway — matched by CVE ID, not by vendor name.