cbcvebase.
CVE-2015-5255
published 2015-11-18

CVE-2015-5255: Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before…

PriorityP427medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
4.48%
90.3th percentile
Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
adobecoldfusion<= 10.0
adobecoldfusion<= 11.0
adobelivecycle_data_services
adobelivecycle_data_services
adobelivecycle_data_services
adobelivecycle_data_services
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.