CVE-2009-3960

CVE Published 2010-02-15
Related Vendor(s) adobe
Related Product(s) blazeds, coldfusion, lifecycle, lifecycle_data_services, flex_data_services
Exploitation Reported (CISA KEV) 2022-03-07
CVSS 3 Base Score 6.5 (MEDIUM)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

References