Security readout for executives and security teams
Plain-English summary
This CVE concerns Axway SecureTransport password-reset API handling. If the researcher report is accurate, an unauthenticated attacker could abuse XML parsing to disclose files, cause denial of service, or trigger server-side requests. Axway disputes the claimed impact, so urgency depends on confirming version, configuration, and exposure.
Executive priority
Treat this as a validation priority for exposed file-transfer systems, not a confirmed emergency. The business risk could be serious if exploitable, but the provided evidence is disputed and lacks confirmed exploitation or CVSS scoring.
Technical view
The CVE describes unauthenticated blind XML injection and XXE in SecureTransport 5.x through 5.3, or through 5.5 with certain REST API configuration. Claimed impacts include local file disclosure, DoS, URI invocation, SSRF, and resultant RCE. Axway states external entities are blocked and impact is not proved.
Likely exposure
Potential exposure is limited to Axway SecureTransport deployments matching the stated 5.x version and REST API resetPassword conditions. Internet-facing or partner-facing managed file transfer portals should be prioritized for inventory. The source bundle does not prove all listed versions are exploitable.
Exploitation context
CISA KEV is false in the provided bundle. Public Exploit-DB, gist, and blog references indicate public research or proof material exists, but the bundle does not confirm active exploitation. The vendor disputes that the issue is a vulnerability.
Researcher notes
Avoid assuming exploitability from the CVE text alone. Correlate version, REST API configuration, XML parser behavior, and Axway’s disputed security notice. Public PoC references should guide defensive validation only, without reproducing offensive steps in production.
Mitigation direction
- Confirm deployed SecureTransport versions and REST API password-reset exposure.
- Review Axway security notices and support guidance for official remediation.
- Restrict unauthenticated access to sensitive REST API surfaces where operationally possible.
- Monitor SecureTransport logs for abnormal resetPassword API activity.
- Prioritize vendor-supported upgrades or configuration changes if Axway recommends them.
Validation and detection
- Inventory SecureTransport 5.x deployments and externally reachable portals.
- Check whether REST API resetPassword functionality is enabled or exposed.
- Compare configuration against Axway security notice guidance.
- Review perimeter logs for suspicious unauthenticated password-reset API requests.
- Document uncertainty where vendor guidance and public research conflict.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
Execution behavior lookup
The CVE wording references code or command execution, so execution technique review may help defensive triage. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCloud metadata behavior lookup
The CVE wording references SSRF or metadata access, so cloud discovery and credential material review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
Open ATT&CK lookupCVE-2019-14277 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.exploit-db.com/exploits/47150CVE reference · x_refsource_MISC
- https://gist.githubusercontent.com/zeropwn/59f17727dfaba239b0ace6f33b752974/raw/9b6541a94ac5ec181a88e6c84cb3e3001025b8fd/Axway%2520SecureTransport%25205.x%2520Unauthenticated%2520XXECVE reference · x_refsource_MISC
- https://zero.lol/2019-07-21-axway-securetransport-xml-injection/CVE reference · x_refsource_MISC
- https://community.axway.com/s/article/SecureTransport-Security-Notice-re-CVE-2019-14277-Unauthenticated-XML-Injection-and-XXECVE reference · x_refsource_CONFIRM
- https://community.axway.com/s/article/SecureTransport-Security-NoticeCVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
