← All CVEs

CVE-2009-3960

medium · 6.5Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-03-07Remediation due 2022-09-07

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

6.5
CVSS
90.0%
EPSS (exploit prob.)
100th
EPSS percentile
2010-02-15
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

VendorProductAffected versions
adobeblazeds<= 3.2
adobecoldfusion7.0.2
adobecoldfusion8.0
adobecoldfusion8.0.1
adobecoldfusion9.0
adobeflex_data_services2.0.1
adobelivecycle8.0.1
adobelivecycle8.2.1
adobelivecycle9.0
adobelivecycle_data_services2.5.1
adobelivecycle_data_services2.6.1
adobelivecycle_data_services3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-3960