CVE-2017-3206
9.8
CRITICAL · CVSS 3.0 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from XML documents embedded within AMF3 messages. If the XML parsing is handled incorrectly it could potentially expose sensitive data on the server, denial of service, or server side request forgery.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.67% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-06-11 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| exadel | flamingo |
References
- http://www.securityfocus.com/bid/97380
- http://www.securityweek.com/flaws-java-amf-libraries-allow-remote-code-execution
- https://codewhitesec.blogspot.com/2017/04/amf.html
- https://www.kb.cert.org/vuls/id/307983
- http://www.securityfocus.com/bid/97380
- http://www.securityweek.com/flaws-java-amf-libraries-allow-remote-code-execution
- https://codewhitesec.blogspot.com/2017/04/amf.html
- https://www.kb.cert.org/vuls/id/307983
→ the Explorer · watch your stack · NVD