{"api_version":"1","generated_at":"2026-07-23T08:32:04+00:00","cve":"CVE-2015-3269","urls":{"html":"https://cve.report/CVE-2015-3269","api":"https://cve.report/api/cve/CVE-2015-3269.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-3269","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-3269"},"summary":{"title":"CVE-2015-3269","description":"Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-08-25 01:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202","name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/archive/1/536266/100/0/threaded","name":"http://www.securityfocus.com/archive/1/536266/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html","name":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Security Bulletin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/","name":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ZDI-22-508 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://marc.info/?l=bugtraq&m=145706712500978&w=2","name":"http://marc.info/?l=bugtraq&m=145706712500978&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'[security bulletin] HPSBGN03550 rev.2 - HP Operations Manager i and BSM using Apache Flex BlazeDS, R' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1033337","name":"http://www.securitytracker.com/id/1033337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle Data Services XML Processing Flaw Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","name":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMSA-2015-0008 | United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html","name":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe Security Bulletin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/76394","name":"http://www.securityfocus.com/bid/76394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle Data Services CVE-2015-3269 XML External Entity Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-3269","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-3269","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"3269","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3269","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3269","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3269","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"3269","vulnerable":"1","versionEndIncluding":"9.26","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"business_service_management","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T05:39:32.110Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202"},{"name":"HPSBGN03550","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=145706712500978&w=2"},{"name":"76394","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/76394"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html"},{"name":"20150819 CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/536266/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html"},{"name":"1033337","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1033337"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-08-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2022-03-11T16:06:33.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202"},{"name":"HPSBGN03550","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=145706712500978&w=2"},{"name":"76394","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/76394"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html"},{"name":"20150819 CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/536266/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html"},{"name":"1033337","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1033337"},{"tags":["x_refsource_MISC"],"url":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2015-3269","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202","refsource":"CONFIRM","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202"},{"name":"HPSBGN03550","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=145706712500978&w=2"},{"name":"76394","refsource":"BID","url":"http://www.securityfocus.com/bid/76394"},{"name":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"name":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html","refsource":"CONFIRM","url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html"},{"name":"20150819 CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/536266/100/0/threaded"},{"name":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html","refsource":"CONFIRM","url":"https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html"},{"name":"1033337","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1033337"},{"name":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/","refsource":"MISC","url":"https://www.zerodayinitiative.com/advisories/ZDI-22-508/"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-3269","datePublished":"2015-08-25T01:00:00.000Z","dateReserved":"2015-04-10T00:00:00.000Z","dateUpdated":"2024-08-06T05:39:32.110Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-08-25 01:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:business_service_management:*:*:*:*:*:*:*:*","versionEndIncluding":"9.26","matchCriteriaId":"939572F4-FE01-4527-985D-B63CCD990C79"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:3.0:*:*:*:*:*:*:*","matchCriteriaId":"2EE5075B-DB11-47F3-9601-F4956ECF5047"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.5:*:*:*:*:*:*:*","matchCriteriaId":"F27B0FB6-04A5-4D6D-9C31-847B924EF836"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.6:*:*:*:*:*:*:*","matchCriteriaId":"16AB3FE1-2860-4A1D-AC3F-79CE04DC1242"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.7:*:*:*:*:*:*:*","matchCriteriaId":"F1172637-AED4-4476-A44B-F7BEF179E9F8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"3269","Ordinal":"1","Title":"CVE-2015-3269","CVE":"CVE-2015-3269","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"3269","Ordinal":"1","NoteData":"Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.","Type":"Description","Title":"CVE-2015-3269"},{"CveYear":"2015","CveId":"3269","Ordinal":"2","NoteData":"2015-08-24","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"3269","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}