Executive brief
Adobe BlazeDS and multiple integrated products are vulnerable to information disclosure via XML external entity (XXE) injection. Remote attackers can obtain sensitive information by sending crafted requests containing malicious external entity references in XML documents.
Affected products
- Adobe BlazeDS 3.2 and earlier
- Adobe LiveCycle 8.0.1, 8.2.1, 9.0
- Adobe LiveCycle Data Services 2.5.1, 2.6.1, 3.0
- Adobe Flex Data Services 2.0.1
- Adobe ColdFusion 7.0.2, 8.0, 8.0.1, 9.0
Timeline
- 2010-02-11: advisory: Vendor advisory APSB10-05 released
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-07: exploited: Reported as exploited in the wild per CISA KEV catalog entry date.