CVE-2011-2092: Input Validation
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2092?
CVE-2011-2092 is rated as a critical vulnerability that may lead to arbitrary code execution.
How do I fix CVE-2011-2092?
To fix CVE-2011-2092, it is recommended to upgrade to the latest version of Adobe LiveCycle or BlazeDS that addresses this vulnerability.
What types of software are affected by CVE-2011-2092?
CVE-2011-2092 affects Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier.
What is the impact of exploiting CVE-2011-2092?
Exploitation of CVE-2011-2092 allows attackers to manipulate the deserialization process, potentially leading to remote code execution.
Is there a workaround for CVE-2011-2092?
While upgrading is recommended, disabling AMF and AMFX data serialization features can serve as a temporary workaround for CVE-2011-2092.