XML External Entity Injection And XML Injection

Description

Security-Assessment.com discovered that multiple Adobe products with different Data Services versions are vulnerable to XML External Entity (XXE) and XML injection attacks. XML external Entities injection allows a wide range of XML based attacks, including local file disclosure, TCP scans and Denial of Service condition, which can be achieved by recursive entity injection, attribute blow up and other types of injection. For more information about the implications associated to this vulnerability, refer to the RFC2518 (17.7 Implications of XML External Entities): http://www.ietf.org/rfc/rfc2518.txt.
The vendor has released several patches for this vulnerability. Consult Web References for more information.

ShareShare on FacebookTweet about this on TwitterShare on Google+

Impact
Information disclosure.

References
Multiple Adobe Products - XML External Entity Injection And XML Injection
Security update available for BlazeDS