CVE-2009-3960
medium · 6.5Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-03-07Remediation due 2022-09-07
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
6.5
CVSS
90.0%
EPSS (exploit prob.)
100th
EPSS percentile
2010-02-15
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | blazeds | <= 3.2 |
| adobe | coldfusion | 7.0.2 |
| adobe | coldfusion | 8.0 |
| adobe | coldfusion | 8.0.1 |
| adobe | coldfusion | 9.0 |
| adobe | flex_data_services | 2.0.1 |
| adobe | livecycle | 8.0.1 |
| adobe | livecycle | 8.2.1 |
| adobe | livecycle | 9.0 |
| adobe | livecycle_data_services | 2.5.1 |
| adobe | livecycle_data_services | 2.6.1 |
| adobe | livecycle_data_services | 3.0 |
Check a specific version with /api/v1/cve/match.
References
- http://secunia.com/advisories/38543
- http://securitytracker.com/id?1023584
- http://www.adobe.com/support/security/bulletins/apsb10-05.html
- http://www.osvdb.org/62292
- http://www.securityfocus.com/bid/38197
- https://www.exploit-db.com/exploits/41855/
- http://secunia.com/advisories/38543
- http://securitytracker.com/id?1023584
- http://www.adobe.com/support/security/bulletins/apsb10-05.html
- http://www.osvdb.org/62292
- http://www.securityfocus.com/bid/38197
- https://www.exploit-db.com/exploits/41855/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2009-3960