HTTP: Adobe Digital Editions Epub XXE Information Disclosure

This signature detects attempts to obtain sensitive information from Adobe Digital Editions. An attacker could gather critical information for further attacks.

Extended Description

Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to information disclosure.

Affected Products

Adobe digital_editions

References

BugTraq: 94879

CVE: CVE-2016-7889

Short Name
HTTP:ADOBE-DIGITAL-INFO-DISC
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Adobe CVE-2016-7889 Digital Disclosure Editions Epub Information XXE bid:94879
Release Date
02/27/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Adobe

CVSS Score

5.0

Found a potential security threat?