SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-5255

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178,…

MEDIUM 4.3EPSS 4.48%

Does this matter?

Lower severity and a low EPSS score (4.48%). Track it; it rarely justifies an emergency change on its own.

Description

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
4.48% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
hp/xp p9000 command view advanced edition · hp/xp7 command view advanced edition · adobe/coldfusion · adobe/livecycle data services
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.