CVE-2009-3960
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Feb 15, 2010
Updated: Dec 19, 2024
Summary
CVE-2009-3960 is a vulnerability affecting BlazeDS 3.2 and earlier versions, used in various Adobe products such as LiveCycle, Flex Data Services, and ColdFusion. This issue allows remote attackers to extract sensitive information via request-related vectors and injected tags or external entity references in XML documents. The specific nature of the vulnerability remains unspecified. Organizations using these impacted Adobe products are advised to apply available patches or upgrades to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe ColdFusion
Affected Vendors
- Adobe