First published: Fri Sep 16 2016(Updated: )
Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe AIR SDK & Compiler | =22.0.0.153 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6936 is considered a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2016-6936, upgrade to Adobe AIR SDK & Compiler version 23.0.0.257 or later.
CVE-2016-6936 affects users of Adobe AIR SDK & Compiler version 22.0.0.153 on Windows.
CVE-2016-6936 is an information disclosure vulnerability related to inadequate transport security for analytics data.
Yes, CVE-2016-6936 can potentially be exploited remotely by attackers with access to the network over which analytics data is transmitted.