{"api_version":"1","generated_at":"2026-07-23T10:47:47+00:00","cve":"CVE-2009-3960","urls":{"html":"https://cve.report/CVE-2009-3960","api":"https://cve.report/api/cve/CVE-2009-3960.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3960","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3960"},"summary":{"title":"CVE-2009-3960","description":"Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.","state":"PUBLISHED","assigner":"adobe","published_at":"2010-02-15 18:30:00","updated_at":"2026-04-21 21:12:29"},"problem_types":["NVD-CWE-noinfo","n/a","CWE-noinfo Not enough information"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960","name":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960","refsource":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://secunia.com/advisories/38543","name":"http://secunia.com/advisories/38543","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Adobe Products XML Processing Information Disclosure - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/41855/","name":"https://www.exploit-db.com/exploits/41855/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"Adobe (Multiple Products) - XML Injection File Content Disclosure - XML webapps Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1023584","name":"http://securitytracker.com/id?1023584","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Adobe BlazeDS Unspecified Flaw Lets Remote Users Access Files on the Target System","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38197","name":"http://www.securityfocus.com/bid/38197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/62292","name":"http://www.osvdb.org/62292","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.adobe.com/support/security/bulletins/apsb10-05.html","name":"http://www.adobe.com/support/security/bulletins/apsb10-05.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable","Vendor Advisory"],"title":"Adobe - Security Bulletins: APSB10-05 Security update available for BlazeDS","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3960","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3960","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[{"source":"ADP","time":"2022-03-07T00:00:00.000Z","lang":"en","value":"CVE-2009-3960 added to CISA KEV"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"blazeds","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"7.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"8.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"flex_data_services","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"8.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"2.6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2009","cve_id":"3960","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"livecycle_data_services","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2009","cve_id":"3960","cve":"CVE-2009-3960","vendorProject":"Adobe","product":"BlazeDS","vulnerabilityName":"Adobe BlazeDS Information Disclosure Vulnerability","dateAdded":"2022-03-07","shortDescription":"Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-09-07","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2009-3960","cwes":"","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2009","cve_id":"3960","cve":"CVE-2009-3960","epss":"0.900120000","percentile":"0.997820000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:45:50.647Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38197","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38197"},{"name":"1023584","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1023584"},{"name":"62292","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/62292"},{"name":"38543","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38543"},{"name":"41855","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/41855/"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-05.html"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2009-3960","options":[{"Exploitation":"active"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2025-02-04T21:42:52.303476Z","version":"2.0.3"},"type":"ssvc"}},{"other":{"content":{"dateAdded":"2022-03-07","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960"},"type":"kev"}}],"problemTypes":[{"descriptions":[{"description":"CWE-noinfo Not enough information","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-10-22T00:05:53.086Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"references":[{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960"}],"timeline":[{"lang":"en","time":"2022-03-07T00:00:00.000Z","value":"CVE-2009-3960 added to CISA KEV"}],"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-02-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-15T09:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"38197","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38197"},{"name":"1023584","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1023584"},{"name":"62292","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/62292"},{"name":"38543","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38543"},{"name":"41855","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/41855/"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-05.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2009-3960","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38197","refsource":"BID","url":"http://www.securityfocus.com/bid/38197"},{"name":"1023584","refsource":"SECTRACK","url":"http://securitytracker.com/id?1023584"},{"name":"62292","refsource":"OSVDB","url":"http://www.osvdb.org/62292"},{"name":"38543","refsource":"SECUNIA","url":"http://secunia.com/advisories/38543"},{"name":"41855","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/41855/"},{"name":"http://www.adobe.com/support/security/bulletins/apsb10-05.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb10-05.html"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2009-3960","datePublished":"2010-02-15T18:00:00.000Z","dateReserved":"2009-11-16T00:00:00.000Z","dateUpdated":"2025-10-22T00:05:53.086Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-02-15 18:30:00","lastModifiedDate":"2026-04-21 21:12:29","problem_types":["NVD-CWE-noinfo","n/a","CWE-noinfo Not enough information"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:N/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*","versionEndIncluding":"3.2","matchCriteriaId":"AEF7C97E-BE99-415D-B12B-D3E7BD9EDF08"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:*","matchCriteriaId":"B015715F-9672-480E-B0AA-968D8C9070D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:*","matchCriteriaId":"DD6C1877-7412-4FBE-9641-334971F9D153"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:8.0.1:*:*:*:*:*:*:*","matchCriteriaId":"28C8D6AF-EDE1-42BD-A47C-2EF8690299BD"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*","matchCriteriaId":"113431FB-E4BE-4416-800C-6B13AD1C0E92"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:flex_data_services:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"B6F65E3F-F3E7-4BE9-A13B-87FFF3B3777E"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.0.1:*:*:*:*:*:*:*","matchCriteriaId":"3890CE6C-D8D0-4406-ACE1-9849CFCA72F4"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:8.2.1:*:*:*:*:*:*:*","matchCriteriaId":"82D29A25-10F2-4FFB-A9BC-B7AAD6D1A18A"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle:9.0:*:*:*:*:*:*:*","matchCriteriaId":"E6804632-7EA5-45AB-91A3-C05D3426CA9F"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.5.1:*:*:*:*:*:*:*","matchCriteriaId":"262ED6C7-3C78-4863-9056-A9D55C7DB6CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:2.6.1:*:*:*:*:*:*:*","matchCriteriaId":"BEFE9CD7-0DB5-4038-AFB5-1B756186605C"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:livecycle_data_services:3.0:*:*:*:*:*:*:*","matchCriteriaId":"2EE5075B-DB11-47F3-9601-F4956ECF5047"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3960","Ordinal":"1","Title":"CVE-2009-3960","CVE":"CVE-2009-3960","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3960","Ordinal":"1","NoteData":"Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.","Type":"Description","Title":"CVE-2009-3960"},{"CveYear":"2009","CveId":"3960","Ordinal":"2","NoteData":"2010-02-15","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3960","Ordinal":"3","NoteData":"2017-08-15","Type":"Other","Title":"Modified"}]}}}