← Zuruck zu CVEs
CVE-2009-3960
MEDIUMCISA KEV6.5
Beschreibung
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
CVE Details
CVSS v3.1 Bewertung6.5
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht2/15/2010
Zuletzt geandert4/21/2026
Quellekev
Honeypot-Sichtungen0
CISA KEV
HerstellerAdobe
ProduktBlazeDS
SchwachstellennameAdobe BlazeDS Information Disclosure Vulnerability
KEV Aufnahmedatum2022-03-07
Behebungsfrist2022-09-07
Ransomware-NutzungKnown
Betroffene Produkte
adobe:blazedsadobe:coldfusionadobe:flex_data_servicesadobe:livecycleadobe:livecycle_data_services
Referenzen
http://secunia.com/advisories/38543(psirt@adobe.com)
http://securitytracker.com/id?1023584(psirt@adobe.com)
http://www.adobe.com/support/security/bulletins/apsb10-05.html(psirt@adobe.com)
http://www.osvdb.org/62292(psirt@adobe.com)
http://www.securityfocus.com/bid/38197(psirt@adobe.com)
https://www.exploit-db.com/exploits/41855/(psirt@adobe.com)
http://secunia.com/advisories/38543(af854a3a-2127-422b-91ae-364da2661108)
http://securitytracker.com/id?1023584(af854a3a-2127-422b-91ae-364da2661108)
http://www.adobe.com/support/security/bulletins/apsb10-05.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/62292(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/38197(af854a3a-2127-422b-91ae-364da2661108)
https://www.exploit-db.com/exploits/41855/(af854a3a-2127-422b-91ae-364da2661108)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960(134c704f-9b21-4f2e-91b3-4a467353bcc0)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.