PT-2015-1584 · Adobe+3 · Flash Player+6

Published

2015-06-09

·

Updated

2016-12-31

·

CVE-2015-3098

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe AIR (affected versions not specified) Adobe Flash Player (affected versions not specified) Adobe AIR SDK (affected versions not specified) Adobe AIR SDK & Compiler (affected versions not specified)
Description The issue is related to a lack of protection for internal data in the software platforms. Exploitation of this issue may allow a remote attacker to bypass access restrictions. The vulnerability exists in several Adobe products and enables remote attackers to bypass domain restriction rules.
Recommendations For Adobe AIR, consider restricting access to sensitive data until a patch is available. For Adobe Flash Player, avoid using sensitive features that may be exploited by remote attackers until the issue is resolved. For Adobe AIR SDK, restrict the use of vulnerable components to minimize the risk of exploitation. For Adobe AIR SDK & Compiler, consider disabling the compilation of sensitive code until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1526
BDU:2015-10907
BDU:2015-10908
BDU:2015-10913
BDU:2015-10914
CVE-2015-3098
MGASA-2015-0248
OPENSUSE-SU-2015_1047-1
RHSA-2015:1086
RHSA-2015_1086
SUSE-SU-2015:1043-1

Affected Products

Alt Linux
Air
Air Sdk
Air Sdk & Compiler
Flash Player
Red Hat
Suse