PT-2015-1583 · Adobe+3 · Flash Player+6
Published
2015-06-09
·
Updated
2016-12-31
·
CVE-2015-3099
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe AIR (affected versions not specified)
Adobe Flash Player (affected versions not specified)
Adobe AIR SDK (affected versions not specified)
Adobe AIR SDK & Compiler (affected versions not specified)
Description
The issue is related to a lack of protection for internal data. Exploitation of this issue may allow a remote attacker to bypass access restrictions. It affects multiple Adobe products and enables remote attackers to bypass domain restriction rules.
Recommendations
For Adobe AIR, consider restricting access to sensitive data until a patch is available.
For Adobe Flash Player, avoid using it for sensitive operations until the issue is resolved.
For Adobe AIR SDK, restrict the use of vulnerable components to minimize the risk of exploitation.
For Adobe AIR SDK & Compiler, consider disabling the compilation of sensitive code until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Red Hat
Suse