Information disclosure in Adobe Captivate - CVE-2017-3087

 

Information disclosure in Adobe Captivate - CVE-2017-3087

Published: June 13, 2017 / Updated: January 12, 2021


Vulnerability identifier: #VU7024
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3087
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information

The weakness exists due to improper input validation. A remote attacker can abuse the quiz reporting feature in Captivate and read arbitrary files on the system.

Successful exploitation of the vulnerability results in information disclosure.

Affected software

Adobe Captivate

How to mitigate CVE-2017-3087

Update to version 10.0.0.192.

Adobe Captivate - update to 10.0.0.192

External References

Related Security Bulletins