CVE-2011-2092 Information

Description

Adobe LiveCycle Data Services 3.1 and earlier LiveCycle 9.0.0.2 and earlier and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data which allows attackers to have an unspecified impact via unknown vectors related to a \deserialization vulnerability.\

Reference

http://www.adobe.com/support/security/bulletins/apsb11-15.html http://www.securitytracker.com/id?1025656 http://www.securitytracker.com/id?1025657

Share on: