Deserialization Vulnerability in Adobe LiveCycle and BlazeDS Products
CVE-2011-2092

Currently unrated

Key Information:

Vendor

Adobe

Status
Vendor
CVE Published:
16 June 2011

What is CVE-2011-2092?

Adobe LiveCycle Data Services and BlazeDS products are affected by a deserialization vulnerability that allows unauthorized class creation during the deserialization of AMF and AMFX data. This flaw can potentially enable attackers to exploit unknown vectors, creating significant security risks to applications utilizing these services.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.