TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2009-3960

MEDIUMCISA KEV
6.5

Beschreibung

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

CVE Details

CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht2/15/2010
Zuletzt geandert4/21/2026
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerAdobe
ProduktBlazeDS
SchwachstellennameAdobe BlazeDS Information Disclosure Vulnerability
KEV Aufnahmedatum2022-03-07
Behebungsfrist2022-09-07
Ransomware-NutzungKnown

Betroffene Produkte

adobe:blazedsadobe:coldfusionadobe:flex_data_servicesadobe:livecycleadobe:livecycle_data_services

Referenzen

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.