VDB

CVE-2015-3269

CVE-2015-3269 PUBLISHED CVSS 5 MEDIUM

Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

EPSS 13.33% · 94.3th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
13.33%
94.3th percentile

Affected Products

VendorProductVersions
hpbusiness_service_management0
n/an/an/a
AdobeColdFusion
adobelivecycle_data_services4.7, 3.0, 4.6
CiscoNexus Dashboard Fabric Controller
VMwareN/A
VMwarevCenter Server

Timeline

  • Aug 18, 2015 CVE Published
  • Aug 19, 2015 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 12, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Jun 16, 2023 EPSS Score
  • Mar 17, 2025 EPSS Score
  • Mar 29, 2025 EPSS Score
  • Mar 30, 2025 EPSS Score
  • May 1, 2025 EPSS Score
  • May 4, 2025 EPSS Score
  • Jun 1, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›