Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability exists in Axway SecureTransport's mail template function, allowing attackers with administrative access to execute arbitrary Java code on the server when an email is sent. This could lead to a full compromise of the affected server.
- Code can be run on servers via email templates.
- Admin-level access enables severe server compromise.
- Confirm if this file transfer product is in use.
Attack Path
How an attacker could exploit the issue
An attacker with administrative access to Axway SecureTransport can exploit a server-side template injection flaw in the mail template feature. This allows them to inject and execute arbitrary Java code when emails are sent, potentially leading to full server compromise.
- Requires administrative privileges.
- Triggered by rendering mail templates.
- Leads to full server compromise.
Live Threat
Current exploitation, exposure, and threat context
A Server-Side Template Injection vulnerability in Axway SecureTransport's mail template functionality could allow an administrator to inject and execute arbitrary Java code expressions on the server. This execution occurs when an email template is rendered, potentially leading to full host compromise.
- Server-side code execution.
- Admin privileges to inject code.
- Full host compromise.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical Server-Side Template Injection vulnerability in Axway SecureTransport requires immediate attention from teams managing the product, likely involving application owners, infrastructure, and security operations. The first practical step is to identify all instances of Axway SecureTransport, confirm their exposure and business criticality, and then ascertain the accountable owner to plan for remediation.
- Own: Application and infrastructure owners.
- Verify: System presence and reachability.
- Action: Plan vendor-coordinated patching.