// For flags

CVE-2009-3960

Adobe BlazeDS Information Disclosure Vulnerability

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Vulnerabilidad sin especificar en BlazeDS v3.2 y anteriores, tal como es utilizado en LiveCycle v8.0.1, v8.2.1 y v9.0, LiveCycle Data Services v2.5.1, v2.6.1 y v3.0, Flex Data Services v2.0.1 y ColdFusion v7.0.2, v8.0, v8.0.1 y v9.0. Permite a atacantes remotos obtener información confidencial a través de vectores de ataque asociados con una petición, y relacionados con una etiqueta inyectada y una referencia a una entidad externa en documentos XML.

Multiple Adobe Products -- XML External Entity Injection. Affected Software: BlazeDS 3.2 and earlier versions, LiveCycle 9.0, 8.2.1, and 8.0.1, LiveCycle Data Services 3.0, 2.6.1, and 2.5.1, Flex Data Services 2.0.1, ColdFusion 9.0, 8.0.1, 8.0, and 7.0.2.

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-11-16 CVE Reserved
  • 2010-02-15 CVE Published
  • 2010-02-22 First Exploit
  • 2022-03-07 Exploited in Wild
  • 2022-09-07 KEV Due Date
  • 2024-07-17 EPSS Updated
  • 2024-08-07 CVE Updated
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Adobe
Search vendor "Adobe"
Blazeds
Search vendor "Adobe" for product "Blazeds"
<= 3.2
Search vendor "Adobe" for product "Blazeds" and version " <= 3.2"
-
Affected
Adobe
Search vendor "Adobe"
Coldfusion
Search vendor "Adobe" for product "Coldfusion"
7.0.2
Search vendor "Adobe" for product "Coldfusion" and version "7.0.2"
-
Affected
Adobe
Search vendor "Adobe"
Coldfusion
Search vendor "Adobe" for product "Coldfusion"
8.0
Search vendor "Adobe" for product "Coldfusion" and version "8.0"
-
Affected
Adobe
Search vendor "Adobe"
Coldfusion
Search vendor "Adobe" for product "Coldfusion"
8.0.1
Search vendor "Adobe" for product "Coldfusion" and version "8.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Coldfusion
Search vendor "Adobe" for product "Coldfusion"
9.0
Search vendor "Adobe" for product "Coldfusion" and version "9.0"
-
Affected
Adobe
Search vendor "Adobe"
Flex Data Services
Search vendor "Adobe" for product "Flex Data Services"
2.0.1
Search vendor "Adobe" for product "Flex Data Services" and version "2.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle
Search vendor "Adobe" for product "Lifecycle"
8.0.1
Search vendor "Adobe" for product "Lifecycle" and version "8.0.1"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle
Search vendor "Adobe" for product "Lifecycle"
8.2.1
Search vendor "Adobe" for product "Lifecycle" and version "8.2.1"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle
Search vendor "Adobe" for product "Lifecycle"
9.0
Search vendor "Adobe" for product "Lifecycle" and version "9.0"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle Data Services
Search vendor "Adobe" for product "Lifecycle Data Services"
2.5.1
Search vendor "Adobe" for product "Lifecycle Data Services" and version "2.5.1"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle Data Services
Search vendor "Adobe" for product "Lifecycle Data Services"
2.6.1
Search vendor "Adobe" for product "Lifecycle Data Services" and version "2.6.1"
-
Affected
Adobe
Search vendor "Adobe"
Lifecycle Data Services
Search vendor "Adobe" for product "Lifecycle Data Services"
3.0
Search vendor "Adobe" for product "Lifecycle Data Services" and version "3.0"
-
Affected