peter bassill · operator
$ cve CVE-2009-3960 JSON

CVE-2009-3960 KEV EXPLOIT

6.5
MEDIUM · CVSS 3.1 · EPSS 90.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-09-07.

Description

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Scoring

CVSS6.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS90.12% — more likely to be exploited than 100% of all CVEs
On CISA KEVyes — remediate by 2022-09-07
Public exploityes
Published2010-02-15
Last modified2026-08-06

CISA KEV

NameAdobe BlazeDS Information Disclosure Vulnerability
Added2022-03-07
Due2022-09-07
Vendor / productAdobe / BlazeDS
Ransomware useknown

Affected (5)

VendorProduct
adobeblazeds
adobecoldfusion
adobeflex data services
adobelivecycle
adobelivecycle data services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD