{"api_version":"1","generated_at":"2026-07-23T11:28:08+00:00","cve":"CVE-2011-2092","urls":{"html":"https://cve.report/CVE-2011-2092","api":"https://cve.report/api/cve/CVE-2011-2092.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-2092","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-2092"},"summary":{"title":"CVE-2011-2092","description":"Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a \"deserialization vulnerability.\"","state":"PUBLISHED","assigner":"adobe","published_at":"2011-06-16 23:55:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1025657","name":"http://www.securitytracker.com/id?1025657","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe BlazeDS Lets Remote Users Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1025656","name":"http://www.securitytracker.com/id?1025656","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle Lets Remote Users Deny Service - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/security/bulletins/apsb11-15.html","name":"http://www.adobe.com/support/security/bulletins/apsb11-15.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe - Security Bulletins: APSB11-15 - Security update available for LiveCycle Data Services, LiveCycle ES, and BlazeDS","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-2092","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-2092","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"4.0.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"blazeds","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.0.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.0.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.2.1.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"9.0.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2011","cve_id":"2092","vulnerable":"1","versionEndIncluding":"3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T22:46:00.887Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1025656","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025656"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-15.html"},{"name":"1025657","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1025657"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-06-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a \"deserialization vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2011-09-07T09:00:00.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"1025656","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025656"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb11-15.html"},{"name":"1025657","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1025657"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2011-2092","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a \"deserialization vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1025656","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025656"},{"name":"http://www.adobe.com/support/security/bulletins/apsb11-15.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb11-15.html"},{"name":"1025657","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1025657"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2011-2092","datePublished":"2011-06-16T23:00:00.000Z","dateReserved":"2011-05-13T00:00:00.000Z","dateUpdated":"2024-08-06T22:46:00.887Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-06-16 23:55:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*","versionEndIncluding":"4.0.1","matchCriteriaId":"007166D5-D7B0-486C-B4B6-C239906EF8D3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:*:*:*:*:*:*:*:*","versionEndIncluding":"3.1","matchCriteriaId":"3FA36866-F153-47DE-871E-D92DBD8A1C2B"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.5:*:*:*:*:*:*:*","matchCriteriaId":"289238E6-C234-4191-911C-C6F0E51A3E1D"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.5.1:*:*:*:*:*:*:*","matchCriteriaId":"262ED6C7-3C78-4863-9056-A9D55C7DB6CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.6:*:*:*:*:*:*:*","matchCriteriaId":"8606C261-650F-43AF-BE2D-52DACFB94BBC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.6.1:*:*:*:*:*:*:*","matchCriteriaId":"BEFE9CD7-0DB5-4038-AFB5-1B756186605C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:3:*:*:*:*:*:*:*","matchCriteriaId":"37973B36-6229-498A-936E-D621E2ED90C6"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:*:*:*:*:*:*:*:*","versionEndIncluding":"9.0.0.2","matchCriteriaId":"9E1BE8C5-F3EA-4F74-8ABE-BB5A7127DED3"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:6.0:*:*:*:*:*:*:*","matchCriteriaId":"123AE8CC-080C-4684-9818-CCEC5ACC1E60"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:7.0:*:*:*:*:*:*:*","matchCriteriaId":"D59B6009-B1B1-4FE1-8330-777473CF9EEA"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3890CE6C-D8D0-4406-ACE1-9849CFCA72F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.0.1.1:*:*:*:*:*:*:*","matchCriteriaId":"55624316-BCFD-4555-92F0-EF5271B86081"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.0.1.2:*:*:*:*:*:*:*","matchCriteriaId":"89AE5D48-8552-4DB5-97A3-4D401559AB81"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.2.1.3:*:*:*:*:*:*:*","matchCriteriaId":"D2C91FA2-9DBB-4B06-8DBF-D7951A947087"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"2092","Ordinal":"1","Title":"CVE-2011-2092","CVE":"CVE-2011-2092","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"2092","Ordinal":"1","NoteData":"Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a \"deserialization vulnerability.\"","Type":"Description","Title":"CVE-2011-2092"},{"CveYear":"2011","CveId":"2092","Ordinal":"2","NoteData":"2011-06-16","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"2092","Ordinal":"3","NoteData":"2011-09-07","Type":"Other","Title":"Modified"}]}}}