CVE-2011-2092
Summary
| CVE | CVE-2011-2092 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-06-16 23:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability." |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Blazeds | All | All | All | All |
| Application | Adobe | Livecycle | 6.0 | All | All | All |
| Application | Adobe | Livecycle | 7.0 | All | All | All |
| Application | Adobe | Livecycle | 8.0.1 | All | All | All |
| Application | Adobe | Livecycle | 8.0.1.1 | All | All | All |
| Application | Adobe | Livecycle | 8.0.1.2 | All | All | All |
| Application | Adobe | Livecycle | 8.2.1.3 | All | All | All |
| Application | Adobe | Livecycle | All | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.5 | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.5.1 | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.6 | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.6.1 | All | All | All |
| Application | Adobe | Livecycle Data Services | 3 | All | All | All |
| Application | Adobe | Livecycle Data Services | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe BlazeDS Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Adobe LiveCycle Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Adobe - Security Bulletins: APSB11-15 - Security update available for LiveCycle Data Services, LiveCycle ES, and BlazeDS | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.