SB2017061303 - Multiple vulnerabilities in Adobe Captivate



SB2017061303 - Multiple vulnerabilities in Adobe Captivate

Published: June 13, 2017 Updated: January 12, 2021

Security Bulletin ID SB2017061303
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2017-3087)

The vulnerability allows a remote attacker to obtain potentially sensitive information

The weakness exists due to improper input validation. A remote attacker can abuse the quiz reporting feature in Captivate and read arbitrary files on the system.

Successful exploitation of the vulnerability results in information disclosure.

2) Input validation error (CVE-ID: CVE-2017-3098)

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to insufficient validation of user-supplied input in the quiz reporting feature. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.


Remediation

Install update from vendor's website.