This application requires Javascript for optimal performance.

Adobe.XML.Entity.Injection

Release Date

Feb 02, 2010

Severity

high

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Description

This indicates an attempt to exploit an XML External Entity Injection vulnerability in Adobe BlazeDS.

The vulnerability is a result of the application's failure to properly sanitize user input before using it in XML. It allows a remote attacker to execute
arbitrary code via sending a crafted web page.

Affected Products

BlazeDS 3.2 and earlier versions
LiveCycle 9.0, 8.2.1, and 8.0.1
LiveCycle Data Services 3.0, 2.6.1, and 2.5.1
Flex Data Services 2.0.1
ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2

Recommended Actions

Apply the latest update from the vendor.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-3960

Reference/s

http://www.adobe.com/support/security/bulletins/apsb10-05.html

Reference: VID-18162