CVE-2009-3960: Adobe BlazeDS Information Disclosure Vulnerability
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Other sources
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2009-3960?
CVE-2009-3960 has been classified as a moderate severity vulnerability due to its potential for information disclosure.
How does CVE-2009-3960 affect Adobe products?
CVE-2009-3960 affects multiple Adobe products including BlazeDS, ColdFusion, and LiveCycle, particularly earlier versions up to 9.0.
How do I fix CVE-2009-3960?
To fix CVE-2009-3960, users should update to the latest patched versions of the affected Adobe products as indicated by Adobe's security updates.
What types of vulnerabilities does CVE-2009-3960 represent?
CVE-2009-3960 represents an information disclosure vulnerability that could expose sensitive data under certain circumstances.
Is CVE-2009-3960 still a concern for current Adobe software users?
While CVE-2009-3960 primarily affects outdated versions, organizations using legacy software should still consider it a potential risk and ensure updates are applied.