CVE-2015-3269
Summary
| CVE | CVE-2015-3269 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-08-25 01:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Livecycle Data Services | 3.0 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.5 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.6 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.7 | All | All | All |
| Application | Hp | Business Service Management | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | Third Party Advisory |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | |
| ZDI-22-508 | Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| '[security bulletin] HPSBGN03550 rev.2 - HP Operations Manager i and BSM using Apache Flex BlazeDS, R' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Adobe LiveCycle Data Services XML Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| VMSA-2015-0008 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | Patch, Vendor Advisory |
| Adobe LiveCycle Data Services CVE-2015-3269 XML External Entity Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.