SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2009-3960

Adobe BlazeDS Information Disclosure Vulnerability

KEVMEDIUM 6.5EPSS 90.0%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 7 September 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
90.01% probability · 100th percentile
CISA KEV
Listed 7 March 2022 · due 7 September 2022 · used in ransomware campaigns
Affected
adobe/blazeds · adobe/coldfusion · adobe/flex data services · adobe/livecycle · adobe/livecycle data services
Source
psirt@adobe.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2009-3960

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.