6.5
CVE-2009-3960
- EPSS 90.01%
- Veröffentlicht 15.02.2010 18:30:00
- Zuletzt bearbeitet 06.08.2026 05:16:33
- Erkennungen
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version 7.0.2
Adobe ≫ Coldfusion Version 8.0
Adobe ≫ Coldfusion Version 8.0.1
Adobe ≫ Coldfusion Version 9.0
Adobe ≫ Flex Data Services Version 2.0.1
Adobe ≫ Livecycle Data Services Version 2.5.1
Adobe ≫ Livecycle Data Services Version 2.6.1
Adobe ≫ Livecycle Data Services Version 3.0
07.03.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Adobe BlazeDS Information Disclosure Vulnerability
SchwachstelleAdobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 90.01% | 0.998 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
| CISA-ADP | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
http://secunia.com/advisories/38543
http://securitytracker.com/id?1023584
http://www.adobe.com/support/security/bulletins/apsb10-05.html
http://www.osvdb.org/62292
http://www.securityfocus.com/bid/38197
https://www.exploit-db.com/exploits/41855/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960