PT-2016-7179 · Adobe · Air Sdk & Compiler
Yakov Shafranovich
·
Published
2016-09-16
·
Updated
2017-08-13
·
CVE-2016-6936
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe AIR SDK & Compiler versions prior to 23.0.0.257
Description
The issue concerns the lack of support for Android runtime-analytics transport security in the affected software, potentially allowing remote attackers to obtain sensitive information by accessing a network over which analytics data is sent.
Recommendations
For versions prior to 23.0.0.257, update to version 23.0.0.257 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Air Sdk & Compiler