CVE-2015-5255: Adobe ColdFusion

Medium severity, CVSS 4.3. EPSS: 4.5% chance of exploitation in the next 30 days.

Adobe BlazeDS, as used in ColdFusion 10 before Update 18 and 11 before Update 7 and LiveCycle Data Services 3.0.x before 3.0.0.354175, 3.1.x before 3.1.0.354180, 4.5.x before 4.5.1.354177, 4.6.2.x before 4.6.2.354178, and 4.7.x before 4.7.0.354178, allows remote attackers to send HTTP traffic to intranet servers via a crafted XML document, related to a Server-Side Request Forgery (SSRF) issue.

Affected products

  • Adobe ColdFusion: up to and including 10.0; up to and including 11.0
  • Adobe Livecycle Data Services: version 3.0 only; version 4.5 only; version 4.6 only; version 4.7 only
  • HP XP7 Command View Advanced Edition: affected versions not specified
  • HP XP p9000 Command View Advanced Edition: affected versions not specified

Published 2015-11-18. Last modified 2026-06-17.