BlazeDS and GraniteDS AMF/AMFX Remote Code Execution Vulnerability

BlazeDS and GraniteDS are prone to a remote code-execution vulnerability.

Successful exploits will allow attackers to execute arbitrary code within the context of the affected application.

Remote attackers can exploit this issue to bypass certain security restrictions.

NOTE: This issue was previously discussed in BID 48267 (Adobe LiveCycle Data Services and BlazeDS APSB11-15 Multiple Remote Vulnerabilities) but has been given its own record to better document it.


 

Privacy Statement
Copyright 2010, SecurityFocus