Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2015-11-18T21:00:00
Updated: 2024-08-06T06:41:08.599Z
Reserved: 2015-07-01T00:00:00
Link: CVE-2015-5255
Vulnrichment
No data.
NVD
Status : Modified
Published: 2015-11-18T21:59:00.130
Modified: 2024-11-21T02:32:39.473
Link: CVE-2015-5255
Redhat
No data.