Description
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."
Remediation
References
http://www.adobe.com/support/security/bulletins/apsb11-15.html
http://www.securitytracker.com/id?1025656
http://www.securitytracker.com/id?1025657
Related Vulnerabilities
CVE-2020-9480 Vulnerability in maven package org.apache.spark:spark-network-common_2.10
CVE-2019-16772 Vulnerability in maven package org.webjars.npm:serialize-to-js
CVE-2021-4278 Vulnerability in npm package tree-kit
CVE-2023-49396 Vulnerability in maven package com.jfinal:jfinal
CVE-2023-42794 Vulnerability in maven package org.apache.tomcat:tomcat