Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:COLDFUSION:XML-CMD-INJ

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Adobe ColdFusion/BlazeDS/LiveCycle XML Command Injection

Release Date

2011/11/17

Update Number

2032

Supported Platforms

idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Adobe ColdFusion/BlazeDS/LiveCycle XML Command Injection


This signature detects attempts to exploit a known flaw in several Adobe server technologies. A successful attack may result in data exposure and/or arbitrary command injection.

Extended Description

Adobe BlazeDS is prone to an XML-injection vulnerability and an XML External Entity injection vulnerability. Attackers can exploit these issues to obtain sensitive information and carry out other attacks. The following applications are affected: BlazeDS 3.2 and earlier versions LiveCycle 9.0, 8.2.1, and 8.0.1 LiveCycle Data Services 3.0, 2.6.1, and 2.5.1 Flex Data Services 2.0.1 ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2

Affected Products

  • Adobe BlazeDS 3.2
  • Adobe ColdFusion 7.0.2
  • Adobe ColdFusion 8.0
  • Adobe ColdFusion 8.0.1
  • Adobe ColdFusion 9.0
  • Adobe Flex Data Services 2.0.1
  • Adobe LiveCycle 8.0.1
  • Adobe LiveCycle 8.2.1
  • Adobe LiveCycle 9.0
  • Adobe LiveCycle Data Services 2.5.1
  • Adobe LiveCycle Data Services 2.6.1
  • Adobe LiveCycle Data Services 3.0

References

  • BugTraq: 38197
  • CVE: CVE-2009-3960
  • URL: http://www.security-assessment.com/files/advisories/2010-02-22_Multiple_Adobe_Products-XML_External_Entity_and_XML_Injection.pdf
  • URL: http://packetstormsecurity.org/files/cve/CVE-2009-3960

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out