{"api_version":"1","generated_at":"2026-07-23T09:29:33+00:00","cve":"CVE-2015-5255","urls":{"html":"https://cve.report/CVE-2015-5255","api":"https://cve.report/api/cve/CVE-2015-5255.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2015-5255","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2015-5255"},"summary":{"title":"CVE-2015-5255","description":"Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-11-18 21:59:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html","name":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Apache Flex BlazeDS 4.7.1 SSRF ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1034210","name":"http://www.securitytracker.com/id/1034210","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe LiveCycle XML Document Processing Flaw Lets Remote Users Conduct Cross-Site Request Forgery Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=145996963420108&w=2","name":"http://marc.info/?l=bugtraq&m=145996963420108&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"'[security bulletin] HPSBST03568 rev.1 - HP XP7 Command View Advanced Edition Suite including Device ' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670","name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Document Display | HPE Support Center","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","name":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VMSA-2015-0008 | United States","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/536958/100/0/threaded","name":"http://www.securityfocus.com/archive/1/536958/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html","name":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe Security Bulletin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html","name":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe Security Bulletin","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/77626","name":"http://www.securityfocus.com/bid/77626","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Adobe Products CVE-2015-5255 Server Side Request Forgery Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2015-5255","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2015-5255","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"10.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"*","cpe7":"update17","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"11.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"*","cpe7":"update6","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"xp7_command_view_advanced_edition","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2015","cve_id":"5255","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"xp_p9000_command_view_advanced_edition","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T06:41:08.599Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"HPSBST03568","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=145996963420108&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html"},{"name":"1034210","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1034210"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html"},{"name":"20151123 CVE-2015-5255: SSRF vulnerability in Apache Flex BlazeDS 4.7.1","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/536958/100/0/threaded"},{"name":"77626","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/77626"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2015-11-17T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"HPSBST03568","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=145996963420108&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html"},{"name":"1034210","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1034210"},{"tags":["x_refsource_CONFIRM"],"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html"},{"name":"20151123 CVE-2015-5255: SSRF vulnerability in Apache Flex BlazeDS 4.7.1","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/536958/100/0/threaded"},{"name":"77626","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/77626"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2015-5255","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"HPSBST03568","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=145996963420108&w=2"},{"name":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html","refsource":"CONFIRM","url":"https://helpx.adobe.com/security/products/coldfusion/apsb15-29.html"},{"name":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html"},{"name":"1034210","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1034210"},{"name":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670","refsource":"CONFIRM","url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670"},{"name":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2015-0008.html"},{"name":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html","refsource":"CONFIRM","url":"https://helpx.adobe.com/security/products/livecycleds/apsb15-30.html"},{"name":"20151123 CVE-2015-5255: SSRF vulnerability in Apache Flex BlazeDS 4.7.1","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/536958/100/0/threaded"},{"name":"77626","refsource":"BID","url":"http://www.securityfocus.com/bid/77626"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2015-5255","datePublished":"2015-11-18T21:00:00.000Z","dateReserved":"2015-07-01T00:00:00.000Z","dateUpdated":"2024-08-06T06:41:08.599Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-11-18 21:59:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:xp_p9000_command_view_advanced_edition:-:*:*:*:*:*:*:*","matchCriteriaId":"7CFCE83E-806F-4E38-8F66-CDB19EB4C4B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:xp7_command_view_advanced_edition:-:*:*:*:*:*:*:*","matchCriteriaId":"49D77644-BF4C-48C1-9D01-B095FF977512"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:*:update17:*:*:*:*:*:*","versionEndIncluding":"10.0","matchCriteriaId":"411765D3-5F0C-406B-BBB0-01318810FF9E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:*:update6:*:*:*:*:*:*","versionEndIncluding":"11.0","matchCriteriaId":"7DE7BFC1-F605-4FA0-8B96-803CC1A63EB2"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:3.0:*:*:*:*:*:*:*","matchCriteriaId":"2EE5075B-DB11-47F3-9601-F4956ECF5047"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.5:*:*:*:*:*:*:*","matchCriteriaId":"F27B0FB6-04A5-4D6D-9C31-847B924EF836"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.6:*:*:*:*:*:*:*","matchCriteriaId":"16AB3FE1-2860-4A1D-AC3F-79CE04DC1242"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:4.7:*:*:*:*:*:*:*","matchCriteriaId":"F1172637-AED4-4476-A44B-F7BEF179E9F8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2015","CveId":"5255","Ordinal":"1","Title":"CVE-2015-5255","CVE":"CVE-2015-5255","Year":"2015"},"notes":[{"CveYear":"2015","CveId":"5255","Ordinal":"1","NoteData":"Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.","Type":"Description","Title":"CVE-2015-5255"},{"CveYear":"2015","CveId":"5255","Ordinal":"2","NoteData":"2015-11-18","Type":"Other","Title":"Published"},{"CveYear":"2015","CveId":"5255","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}