SB2017061303 - Multiple vulnerabilities in Adobe Captivate
Published: June 13, 2017 Updated: January 12, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2017-3087)
The vulnerability allows a remote attacker to obtain potentially sensitive informationThe weakness exists due to improper input validation. A remote attacker can abuse the quiz reporting feature in Captivate and read arbitrary files on the system.
Successful exploitation of the vulnerability results in information disclosure.
2) Input validation error (CVE-ID: CVE-2017-3098)
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in the quiz reporting feature. A remote attacker can pass specially crafted input to the application and execute arbitrary code on the system.
Remediation
Install update from vendor's website.