JVNDB-2015-004431
|
Adobe LiveCycle Data Services �Ȃǂ̐��i�� flex-messaging-core.jar �Ŏg�p����� Apache Flex BlazeDS �ɂ�����C�ӂ̃t�@�C����ǂ܂��Ǝ㐫
|
Adobe LiveCycle Data Services (LCDS) �Ȃǂ̐��i�� flex-messaging-core.jar �Ŏg�p����� Apache Flex BlazeDS �ɂ́A�C�ӂ̃t�@�C����ǂ܂��Ǝ㐫�����݂��܂��B
�{���́AXML �O���G���e�B�e�B (XXE) �̖��Ɋւ���Ǝ㐫�ł��B
|
CVSS v2 �ɂ��[���x ��{�l: 5.0 (�x��) [NVD�l]
- �U�����敪: �l�b�g���[�N
- �U�������̕��G��: ��
- �U���O�̔F�ؗv��: �s�v
- �@�����ւ̉e��(C): �����I
- ���S���ւ̉e��(I): �Ȃ�
- �p���ւ̉e��(A): �Ȃ�
|
|
�A�h�r�V�X�e���Y
- Adobe LiveCycle Data Services 3.0.0.354170 ������ 3.0.x
- Adobe LiveCycle Data Services 4.5.1.354169 ������ 4.5
- Adobe LiveCycle Data Services 4.6.2.354169 ������ 4.6.2
- Adobe LiveCycle Data Services 4.7.0.354169 ������ 4.7
����
- Hitachi Automation Director
- Hitachi Compute Systems Manager Software (�C�O��)
- Hitachi Compute Systems Manager Software (������)
- Hitachi Device Manager Software
- Hitachi IT Operations Director
- Job Management Partner 1/Automatic Operation
- Job Management Partner 1/IT Desktop Management 2 - Manager
- Job Management Partner 1/IT Desktop Management - Manager
- JP1/Automatic Operation
- JP1/IT Desktop Management 2 - Manager
- JP1/IT Desktop Management - Manager
|
�A�h�r�V�X�e���Y���i�Ɋւ��āF Windows ����� Linux ��ʼnғ������L�o�[�W�����̐��i���A�{�Ǝ㐫�̉e�����܂��B
�{�Ǝ㐫�̉e������������i�̏ڍׂɂ��ẮA�x���_��� HS16-005 �������m�F���������B
|
��O�҂ɂ��A�G���e�B�e�B�Q�ƂɊ֘A���� XML �O���G���e�B�e�B�錾���܂� AMF ���b�Z�[�W����āA�C�ӂ̃t�@�C����ǂ܂��\��������܂��B
|
�x���_��萳���ȑ��J����Ă��܂��B�x���_�����Q�Ƃ��ēK�ȑ�����{���Ă��������B
|
�A�h�r�V�X�e���Y
����
- Hitachi Software Vulnerability Information : HS16-005
- Hitachi Software Vulnerability Information : HS15-028
- Hitachi Software Vulnerability Information : HS16-009
- �\�t�g�E�F�A���i�Z�L�����e�B��� : HS16-005
- �\�t�g�E�F�A���i�Z�L�����e�B��� : HS15-028
- �\�t�g�E�F�A���i�Z�L�����e�B��� : HS16-009
|
- ���R����(CWE-200) [NVD�]��]
|
- CVE-2015-3269
|
- National Vulnerability Database (NVD) : CVE-2015-3269
- �֘A���� : CVE-2015-3269 Apache Flex BlazeDS Insecure Xml Entity Expansion Vulnerability
|
- [2015�N08��27��]
�f��
[2016�N02��15��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (HS16-005) ��lj�
[2016�N02��22��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (HS15-028) ��lj�
[2016�N03��24��]
�e������V�X�e���F�x���_���̒lj��ɔ������e���X�V
�x���_���F���� (HS16-009) ��lj�
|