CVE-2011-2093
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object…
Does this matter?
Lower severity and a low EPSS score (3.77%). Track it; it rarely justifies an emergency change on its own.
Description
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object graph vulnerability."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
- EPSS
- 3.77% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- adobe/blazeds · adobe/livecycle data services · adobe/livecycle
- Source
- psirt@adobe.com
References
- http://osvdb.org/73009
- http://www.adobe.com/support/security/bulletins/apsb11-15.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/48267
- http://www.securitytracker.com/id?1025656
- http://www.securitytracker.com/id?1025657
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68026
- http://osvdb.org/73009
- http://www.adobe.com/support/security/bulletins/apsb11-15.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/48267
- http://www.securitytracker.com/id?1025656
- http://www.securitytracker.com/id?1025657
- https://exchange.xforce.ibmcloud.com/vulnerabilities/68026
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.