CVE-2009-3960: Adobe BlazeDS Information Disclosure Vulnerability

Published Feb 15, 2010
·
Updated

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

Other sources

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Affected Software

19 affected components
Adobe BlazeDS
Adobe BlazeDS<=3.2
Adobe ColdFusion=7.0.2
Adobe ColdFusion=8.0
Adobe ColdFusion=8.0.1
Adobe ColdFusion=9.0
Adobe Flex Data Services=2.0.1
Adobe LifeCycle=8.0.1
Adobe LifeCycle=8.2.1
Adobe LifeCycle=9.0
Adobe Lifecycle Data Services=2.5.1
Adobe Lifecycle Data Services=2.6.1
Adobe Lifecycle Data Services=3.0
Adobe LiveCycle=8.0.1
Adobe LiveCycle=8.2.1
Adobe LiveCycle=9.0
Adobe LiveCycle Data Services=2.5.1
Adobe LiveCycle Data Services=2.6.1
Adobe LiveCycle Data Services=3.0

Event History

Feb 15, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityAffected Software
Mar 7, 2022
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
Feb 19, 2025
News Published
via BleepingComputer·08:55 PM
Feb 20, 2025
News Published
via BleepingComputer·12:41 AM

Peer vulnerabilities

Found alongside the following vulnerabilities.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2009-3960?

CVE-2009-3960 has been classified as a moderate severity vulnerability due to its potential for information disclosure.

2

How does CVE-2009-3960 affect Adobe products?

CVE-2009-3960 affects multiple Adobe products including BlazeDS, ColdFusion, and LiveCycle, particularly earlier versions up to 9.0.

3

How do I fix CVE-2009-3960?

To fix CVE-2009-3960, users should update to the latest patched versions of the affected Adobe products as indicated by Adobe's security updates.

4

What types of vulnerabilities does CVE-2009-3960 represent?

CVE-2009-3960 represents an information disclosure vulnerability that could expose sensitive data under certain circumstances.

5

Is CVE-2009-3960 still a concern for current Adobe software users?

While CVE-2009-3960 primarily affects outdated versions, organizations using legacy software should still consider it a potential risk and ensure updates are applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203