Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities
23 Apr. 2012
Summary
This allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Adobe BlazeDS is prone to an XML-injection vulnerability and an XML External Entity injection vulnerability.
Attackers can exploit these issues to obtain sensitive information and carry out other attacks.
Vendor Status:
Adobe as issued an update for this vulnerablity.