CVE-2009-3960

Scores

EPSS

0.901high90.1%
0%20%40%60%80%100%

Percentile: 90.1%

CVSS

6.5medium3.x
0246810

CVSS Score: 6.5/10

All CVSS Scores

CVSS 3.x
6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVSS 2.0
4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Description

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

Related Vulnerabilities

Exploits

Exploit ID: CVE-2009-3960

Source: cisa

URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Exploit ID: 11529

Source: exploitdb

URL: https://www.exploit-db.com/exploits/11529

Exploit ID: 41855

Source: exploitdb

URL: https://www.exploit-db.com/exploits/41855

Vulnerable Software (5)

Type: Configuration

Vendor: *

Product: blazeds

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:adobe:coldf...

Source: nvd

Type: Configuration

Vendor: *

Product: coldfusion

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:adobe:coldf...

Source: nvd

Type: Configuration

Vendor: *

Product: flex_data_services

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:adobe:coldf...

Source: nvd

Type: Configuration

Vendor: *

Product: livecycle

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:adobe:coldf...

Source: nvd

Type: Configuration

Vendor: *

Product: livecycle_data_services

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:*",      "versionEndIncluding": "3.2",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:adobe:coldf...

Source: nvd

End of list