Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-5255


Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.


Published

2015-11-18T21:59:00.130

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application hp xp_p9000_command_view_advanced_edition - Yes
Application hp xp7_command_view_advanced_edition - Yes
Application adobe coldfusion ≤ 10.0 Yes
Application adobe coldfusion ≤ 11.0 Yes
Application adobe livecycle_data_services 3.0 Yes
Application adobe livecycle_data_services 4.5 Yes
Application adobe livecycle_data_services 4.6 Yes
Application adobe livecycle_data_services 4.7 Yes

References