CVE-2015-5255
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178,…
Does this matter?
Lower severity and a low EPSS score (4.48%). Track it; it rarely justifies an emergency change on its own.
Description
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 4.48% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- hp/xp p9000 command view advanced edition · hp/xp7 command view advanced edition · adobe/coldfusion · adobe/livecycle data services
- Source
- secalert@redhat.com
References
- http://marc.info/?l=bugtraq&m=145996963420108&w=2Third Party Advisory
- http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html
- http://www.securityfocus.com/archive/1/536958/100/0/threaded
- http://www.securityfocus.com/bid/77626
- http://www.securitytracker.com/id/1034210
- http://www.vmware.com/security/advisories/VMSA-2015-0008.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670Third Party Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb15-29.htmlPatch, Vendor Advisory
- https://helpx.adobe.com/security/products/livecycleds/apsb15-30.htmlPatch, Vendor Advisory
- http://marc.info/?l=bugtraq&m=145996963420108&w=2Third Party Advisory
- http://packetstormsecurity.com/files/134506/Apache-Flex-BlazeDS-4.7.1-SSRF.html
- http://www.securityfocus.com/archive/1/536958/100/0/threaded
- http://www.securityfocus.com/bid/77626
- http://www.securitytracker.com/id/1034210
- http://www.vmware.com/security/advisories/VMSA-2015-0008.html
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05073670Third Party Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb15-29.htmlPatch, Vendor Advisory
- https://helpx.adobe.com/security/products/livecycleds/apsb15-30.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.