Loading
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified impact via unknown vectors, related to a "deserialization vulnerability."
Use CWE-20, Adobe vendor hub and Blazeds product page to widen CVE-2011-2092 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-3960 and CVE-2011-2093 for nearby disclosures in the same product family.