CVE-2015-3269 describes an XML External Entity (XXE) vulnerability in Apache Flex BlazeDS, affecting various versions of Adobe LiveCycle Data Services (LCDS) and other products like HP Business Service Management. This flaw allows unauthenticated remote attackers to read arbitrary files on the system by sending a specially crafted AMF message containing an XML external entity declaration. The vulnerability has a CVSS score of 5.0, indicating a medium severity, with a low attack complexity and potential for confidentiality impact. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.26CPE matchmatch criteria | cpe:2.3:a:hp:business_service_management:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle_data_services:3.0:*:*:*:*:*:*:* | ||
4.5CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle_data_services:4.5:*:*:*:*:*:*:* | ||
4.6CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle_data_services:4.6:*:*:*:*:*:*:* | ||
4.7CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle_data_services:4.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] HP Operations Manager i flex-messaging-core.jar XML External Entity (XXE) Injection Remote Information Disclosure
Mar 15, 2016[R1] HP Operations Manager i flex-messaging-core.jar XML External Entity (XXE) Injection Remote Information Disclosure
Mar 14, 2016[R1] HP Operations Manager i flex-messaging-core.jar XML External Entity (XXE) Injection Remote Information Disclosure
Mar 14, 2016