CVE-2009-3960
בינונית 6.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe BlazeDS Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-24/7/2026
מוצרים מושפעים
adobe: blazeds; adobe: coldfusion; adobe: flex data services; adobe: livecycle; adobe: livecycle data services
קישורים
- http://www.adobe.com/support/security/bulletins/apsb10-05.html Not ApplicableVendor Advisory
- http://www.adobe.com/support/security/bulletins/apsb10-05.html Not ApplicableVendor Advisory
- https://www.exploit-db.com/exploits/41855/ ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41855/ ExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/38543 Broken Link
- http://securitytracker.com/id?1023584 Broken LinkThird Party AdvisoryVDB Entry
- http://www.osvdb.org/62292 Broken Link
- http://www.securityfocus.com/bid/38197 Broken LinkThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/38543 Broken Link
- http://securitytracker.com/id?1023584 Broken LinkThird Party AdvisoryVDB Entry