6.5
CVE-2009-3960
- EPSS 86.27%
- Published 15.02.2010 18:30:00
- Last modified 11.04.2025 00:51:21
- Source psirt@adobe.com
- Teams watchlist Login
- Open Login
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Data is provided by the National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version7.0.2
Adobe ≫ Coldfusion Version8.0
Adobe ≫ Coldfusion Version8.0.1
Adobe ≫ Coldfusion Version9.0
Adobe ≫ Flex Data Services Version2.0.1
Adobe ≫ Livecycle Data Services Version2.5.1
Adobe ≫ Livecycle Data Services Version2.6.1
Adobe ≫ Livecycle Data Services Version3.0
07.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Adobe BlazeDS Information Disclosure Vulnerability
VulnerabilityAdobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
DescriptionApply updates per vendor instructions.
Required actionsType | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 86.27% | 0.994 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|