BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
BID:48279
Info
BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
| Bugtraq ID: | 48279 |
| Class: | Unknown |
| CVE: |
CVE-2011-2092 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 14 2011 12:00AM |
| Updated: | May 01 2012 05:21PM |
| Credit: | Wouter Coekaerts |
| Vulnerable: |
HP Systems Insight Manager 6.3 HP Systems Insight Manager 6.2 HP Systems Insight Manager 6.1 HP Systems Insight Manager 6.0.0.96 HP Systems Insight Manager 6.0 HP Systems Insight Manager 5.3 Update 1 HP Systems Insight Manager 5.3 HP Systems Insight Manager 5.2 SP2 HP Systems Insight Manager 5.1 SP1 HP Systems Insight Manager 5.0 SP6 HP Systems Insight Manager 5.0 SP5 HP Systems Insight Manager 5.0 SP3 HP Systems Insight Manager 5.0 SP2 HP Systems Insight Manager 5.0 SP1 HP Systems Insight Manager 5.0 HP Systems Insight Manager 4.2 SP2 HP Systems Insight Manager 4.2 SP1 HP Systems Insight Manager 4.2 Granite Software GraniteDS 2.2 Adobe LifeCycle Data Services 2.6.1 Adobe LifeCycle Data Services 3.1 Adobe LifeCycle Data Services 2.5.1 Adobe LifeCycle 9.0.0.2 Adobe LifeCycle 8.2.1.3 Adobe LifeCycle 8.0.1.3 Adobe BlazeDS 4.0.1 |
| Not Vulnerable: |
HP Systems Insight Manager 7.0 Granite Software GraniteDS 2.2.1 |
Discussion
BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
BlazeDS and GraniteDS are prone to a remote code-execution vulnerability.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected application.
Remote attackers can exploit this issue to bypass certain security restrictions.
NOTE: This issue was previously discussed in BID 48267 (Adobe LiveCycle Data Services and BlazeDS APSB11-15 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
BlazeDS and GraniteDS are prone to a remote code-execution vulnerability.
Successful exploits will allow attackers to execute arbitrary code within the context of the affected application.
Remote attackers can exploit this issue to bypass certain security restrictions.
NOTE: This issue was previously discussed in BID 48267 (Adobe LiveCycle Data Services and BlazeDS APSB11-15 Multiple Remote Vulnerabilities) but has been given its own record to better document it.
Exploit / POC
BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
Solution:
Remote attackers can exploit these issues crash the affected applications or bypass certain security restrictions.
Adobe BlazeDS 4.0.1
Solution:
Remote attackers can exploit these issues crash the affected applications or bypass certain security restrictions.
Adobe BlazeDS 4.0.1
-
Adobe blz401_hf_21287.zip
http://download.macromedia.com/pub/security/bulletins/blz401_hf_21287. zip
References
BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability
References:
References:
- Adobe Homepage (Adobe)
- GraniteDS AMF3 Object Deserialization Vulnerability (Granited Services)
- Security update available for LiveCycle Data Services, LiveCycle ES, and BlazeDS (Adobe)