CVE-2009-3960
Adobe BlazeDS Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 7 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 90.01% probability · 100th percentile
- CISA KEV
- Listed 7 March 2022 · due 7 September 2022 · used in ransomware campaigns
- Affected
- adobe/blazeds · adobe/coldfusion · adobe/flex data services · adobe/livecycle · adobe/livecycle data services
- Source
- psirt@adobe.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-3960
References
- http://secunia.com/advisories/38543Broken Link
- http://securitytracker.com/id?1023584Broken Link, Third Party Advisory, VDB Entry
- http://www.adobe.com/support/security/bulletins/apsb10-05.htmlNot Applicable, Vendor Advisory
- http://www.osvdb.org/62292Broken Link
- http://www.securityfocus.com/bid/38197Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41855/Exploit, Third Party Advisory, VDB Entry
- http://secunia.com/advisories/38543Broken Link
- http://securitytracker.com/id?1023584Broken Link, Third Party Advisory, VDB Entry
- http://www.adobe.com/support/security/bulletins/apsb10-05.htmlNot Applicable, Vendor Advisory
- http://www.osvdb.org/62292Broken Link
- http://www.securityfocus.com/bid/38197Broken Link, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41855/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.