← Vulnerability feed

Vulnerability record · CVE-2011-2093 · published 16 June 2011

CVE-2011-2093: Adobe blazeds improper input validation vulnerability

Adobe · Blazeds

Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object graph vulnerability."

5.0 CVSS 2.0 Medium EPSS 3.8% · top 10.4% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly handle object graphs, which allows attackers to cause a denial of service via unspecified vectors, related to a "complex object graph vulnerability."

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2011-2093 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.5CVE-2009-3960Adobe BlazeDS XML External Entity Information DisclosureBlazeDS 3.2 and earlier, along with related LiveCycle, LiveCycle Data Services, Flex Data Services, and ColdFusion versions, mishandles XML documents…KEVEPSS 90%analysed10.0CVE-2011-2092Adobe blazeds improper input validation vulnerabilityAdobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of clas…EPSS 6.1%6.1CVE-2016-6934Adobe experience manager forms cross-site scripting vulnerabilityAdobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the PMAdmin module that…EPSS 2.6%6.1CVE-2016-6933Adobe experience manager cross-site scripting vulnerabilityAdobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the AACComponent that c…EPSS 2.0%5.0CVE-2015-3269Hp business service management information exposure vulnerabilityApache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4…EPSS 9.8%4.3CVE-2015-5255Hp xp p9000 command view advanced edition improper input validation vulnerabilityAdobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3…EPSS 4.5%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2011-2093), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.