CVE-2009-3960
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Published
2010-02-15T18:30:00.407
Last Modified
2025-10-22T01:15:35.130
Status
Deferred
Source
[email protected]
Severity
CVSSv3.1: 6.5 (MEDIUM)
CVSSv2 Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
- Access Vector: NETWORK
- Access Complexity: MEDIUM
- Authentication: NONE
- Confidentiality Impact: PARTIAL
- Integrity Impact: NONE
- Availability Impact: NONE
Exploitability Score
8.6
Impact Score
2.9
Weaknesses
-
Type: Primary
NVD-CWE-noinfo
Affected Vendors & Products
References
-
http://secunia.com/advisories/38543
Broken Link
([email protected])
-
http://securitytracker.com/id?1023584
Broken Link, Third Party Advisory, VDB Entry
([email protected])
-
http://www.adobe.com/support/security/bulletins/apsb10-05.html
Not Applicable, Vendor Advisory
([email protected])
-
http://www.osvdb.org/62292
Broken Link
([email protected])
-
http://www.securityfocus.com/bid/38197
Broken Link, Third Party Advisory, VDB Entry
([email protected])
-
https://www.exploit-db.com/exploits/41855/
Exploit, Third Party Advisory, VDB Entry
([email protected])
-
http://secunia.com/advisories/38543
Broken Link
(af854a3a-2127-422b-91ae-364da2661108)
-
http://securitytracker.com/id?1023584
Broken Link, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.adobe.com/support/security/bulletins/apsb10-05.html
Not Applicable, Vendor Advisory
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.osvdb.org/62292
Broken Link
(af854a3a-2127-422b-91ae-364da2661108)
-
http://www.securityfocus.com/bid/38197
Broken Link, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.exploit-db.com/exploits/41855/
Exploit, Third Party Advisory, VDB Entry
(af854a3a-2127-422b-91ae-364da2661108)
-
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960
(134c704f-9b21-4f2e-91b3-4a467353bcc0)