← Back

CVE-2009-3960

nvd nist
Published: Feb 15, 2010Modified: Apr 21, 2026CISA KEV

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Affected (12)

5 products
Blazeds
Coldfusion
Flex Data Services
Livecycle
Livecycle Data Services
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.2
Adobe
Version 7.0.2
Version 8.0.1
Version 8.0
Version 9.0
Version 2.0.1
Adobe
Version 8.0.1
Version 8.2.1
Version 9.0
Adobe
Version 2.5.1
Version 2.6.1
Version 3.0

References (13)

Source: psirt@adobe.com
Broken Link
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Not ApplicableVendor Advisory
Source: psirt@adobe.com
Broken Link
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.