CVE-2015-5255
Summary
| CVE | CVE-2015-5255 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-18 21:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Coldfusion | All | update17 | All | All |
| Application | Adobe | Coldfusion | All | update6 | All | All |
| Application | Adobe | Livecycle Data Services | 3.0 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.5 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.6 | All | All | All |
| Application | Adobe | Livecycle Data Services | 4.7 | All | All | All |
| Application | Hp | Xp7 Command View Advanced Edition | - | All | All | All |
| Application | Hp | Xp P9000 Command View Advanced Edition | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Flex BlazeDS 4.7.1 SSRF ≈ Packet Storm | af854a3a-2127-422b-91ae-364da2661108 | packetstormsecurity.com | |
| Adobe LiveCycle XML Document Processing Flaw Lets Remote Users Conduct Cross-Site Request Forgery Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| '[security bulletin] HPSBST03568 rev.1 - HP XP7 Command View Advanced Edition Suite including Device ' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | Third Party Advisory |
| Document Display | HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | Third Party Advisory |
| VMSA-2015-0008 | United States | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | Patch, Vendor Advisory |
| Adobe Security Bulletin | af854a3a-2127-422b-91ae-364da2661108 | helpx.adobe.com | Patch, Vendor Advisory |
| Multiple Adobe Products CVE-2015-5255 Server Side Request Forgery Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.