Junglewise Threat Intelligence

CVE-2009-3960: Adobe BlazeDS Information Disclosure Vulnerability

CVE-2009-3960 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-03-07

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe BlazeDS and multiple integrated products are vulnerable to information disclosure via XML external entity (XXE) injection. Remote attackers can obtain sensitive information by sending crafted requests containing malicious external entity references in XML documents.

Affected products

  • Adobe BlazeDS 3.2 and earlier
  • Adobe LiveCycle 8.0.1, 8.2.1, 9.0
  • Adobe LiveCycle Data Services 2.5.1, 2.6.1, 3.0
  • Adobe Flex Data Services 2.0.1
  • Adobe ColdFusion 7.0.2, 8.0, 8.0.1, 9.0

Timeline

  • 2010-02-11: advisory: Vendor advisory APSB10-05 released
  • 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-07: exploited: Reported as exploited in the wild per CISA KEV catalog entry date.