CVE-2009-3960 is an unspecified vulnerability in Adobe BlazeDS and related products like LiveCycle, LiveCycle Data Services, Flex Data Services, and ColdFusion. It allows remote attackers to obtain sensitive information through XML injection and external entity references. With a CVSS score of 6.5 (MEDIUM), it has a high confidentiality impact, requiring no privileges and low attack complexity, though user interaction is required. This vulnerability is actively exploited, including in known ransomware campaigns, and has publicly available exploit modules in Metasploit and ExploitDB, garnering significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2CPE matchmatch criteria | cpe:2.3:a:adobe:blazeds:*:*:*:*:*:*:*:* | ||
7.0.2CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:7.0.2:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:8.0:*:*:*:*:*:*:* | ||
8.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:8.0.1:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.