CVE-2009-3960
Summary
| CVE | CVE-2009-3960 |
|---|---|
| State | PUBLISHED |
| Assigner | adobe |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-02-15 18:30:00 UTC |
| Updated | 2026-04-21 21:12:29 UTC |
| Description | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS: 0.900120000 probability, percentile 0.997810000 (date 2026-07-21)
CISA KEV: Listed on 2022-03-07; due 2022-09-07; ransomware use Known
Problem Types: NVD-CWE-noinfo | n/a | CWE-noinfo Not enough information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | ADP | DECLARED | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
CISA Known Exploited Vulnerability
| Vendor | Adobe |
|---|---|
| Product | BlazeDS |
| Name | Adobe BlazeDS Information Disclosure Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2009-3960 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Blazeds | All | All | All | All |
| Application | Adobe | Coldfusion | 7.0.2 | All | All | All |
| Application | Adobe | Coldfusion | 8.0 | All | All | All |
| Application | Adobe | Coldfusion | 8.0.1 | All | All | All |
| Application | Adobe | Coldfusion | 9.0 | All | All | All |
| Application | Adobe | Flex Data Services | 2.0.1 | All | All | All |
| Application | Adobe | Livecycle | 8.0.1 | All | All | All |
| Application | Adobe | Livecycle | 8.2.1 | All | All | All |
| Application | Adobe | Livecycle | 9.0 | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.5.1 | All | All | All |
| Application | Adobe | Livecycle Data Services | 2.6.1 | All | All | All |
| Application | Adobe | Livecycle Data Services | 3.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| Adobe Products XML Processing Information Disclosure - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Broken Link |
| Adobe (Multiple Products) - XML Injection File Content Disclosure - XML webapps Exploit | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| SecurityTracker.com Archives - Adobe BlazeDS Unspecified Flaw Lets Remote Users Access Files on the Target System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Broken Link, Third Party Advisory, VDB Entry |
| Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Broken Link, Third Party Advisory, VDB Entry |
| www.osvdb.org/62292 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| Adobe - Security Bulletins: APSB10-05 Security update available for BlazeDS | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Not Applicable, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2022-03-07T00:00:00.000Z | CVE-2009-3960 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.