TROYANOSYVIRUS
Volver a CVEs

CVE-2009-3960

MEDIUMCISA KEV
6.5

Descripcion

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Detalles CVE

Puntuacion CVSS v3.16.5
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado2/15/2010
Ultima modificacion4/21/2026
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorAdobe
ProductoBlazeDS
Nombre vulnerabilidadAdobe BlazeDS Information Disclosure Vulnerability
Fecha inclusion KEV2022-03-07
Fecha limite remediacion2022-09-07
Uso en ransomwareKnown

Productos afectados

adobe:blazedsadobe:coldfusionadobe:flex_data_servicesadobe:livecycleadobe:livecycle_data_services

Referencias

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.