VDB
CVE-2015-3269
CVE-2015-3269
PUBLISHED
CVSS 5 MEDIUM
Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4.6.2 before 4.6.2.354169, and 4.7 before 4.7.0.354169 and other products, allows remote attackers to read arbitrary files via an AMF message containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
EPSS 13.33% · 94.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
13.33%
94.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| hp | business_service_management | 0 |
| n/a | n/a | n/a |
| Adobe | ColdFusion | |
| adobe | livecycle_data_services | 4.7, 3.0, 4.6 |
| Cisco | Nexus Dashboard Fabric Controller | |
| VMware | N/A | |
| VMware | vCenter Server |
Timeline
- Aug 18, 2015 CVE Published
- Aug 19, 2015 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 12, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Jun 16, 2023 EPSS Score
- Mar 17, 2025 EPSS Score
- Mar 29, 2025 EPSS Score
- Mar 30, 2025 EPSS Score
- May 1, 2025 EPSS Score
- May 4, 2025 EPSS Score
- Jun 1, 2025 EPSS Score
References
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05026202 url
- HPSBGN03550 vendor-advisory
- 76394 vdb
- http://www.vmware.com/security/advisories/VMSA-2015-0008.html url
- https://helpx.adobe.com/security/products/livecycleds/apsb15-20.html url
- 20150819 CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability mailing-list
- https://helpx.adobe.com/content/help/en/security/products/coldfusion/apsb15-21.html url
- 1033337 vdb
- https://www.zerodayinitiative.com/advisories/ZDI-22-508/ url
- https://nvd.nist.gov/vuln/detail/CVE-2015-3269 advisory
- https://www.zerodayinitiative.com/advisories/ZDI-22-508 url
- https://www.zerodayinitiative.com/advisories/ZDI-CAN-14806/ advisory
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz62623 advisory
- https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvz62628 advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb15-21.html advisory