← Back

CVE-2011-2092

nvd nist
Published: Jun 16, 2011Modified: Apr 29, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."

Affected (14)

3 products
Blazeds
Livecycle Data Services
Livecycle
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.0.1
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Up to 3.1
Version 2.5.1
Version 2.5
Version 2.6.1
Version 2.6
Version 3
Configuration C
7 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Up to 9.0.0.2
Version 6.0
Version 7.0
Version 8.0.1.1
Version 8.0.1.2
Version 8.0.1
Version 8.2.1.3

References (6)

Source: psirt@adobe.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.