Vulnerability Name: | CVE-2009-3960 (CCN-56259) | ||||||||
Assigned: | 2009-11-16 | ||||||||
Published: | 2010-02-11 | ||||||||
Updated: | 2017-08-16 | ||||||||
Summary: | Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-noinfo | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2009-3960 Source: CCN Type: SA38543 Adobe Products XML Processing Information Disclosure Source: SECUNIA Type: UNKNOWN 38543 Source: CCN Type: SECTRACK ID: 1023584 Adobe BlazeDS Unspecified Flaw Lets Remote Users Access Files on the Target System Source: SECTRACK Type: UNKNOWN 1023584 Source: CONFIRM Type: Vendor Advisory http://www.adobe.com/support/security/bulletins/apsb10-05.html Source: CCN Type: Adobe Product Security Bulletin APSB10-06 Security update available for Adobe Flash Player Source: OSVDB Type: UNKNOWN 62292 Source: CCN Type: OSVDB ID: 62292 Adobe Multiple Products BlazeDS XML Request Handling Information Disclosure Source: BID Type: UNKNOWN 38197 Source: CCN Type: BID-38197 Adobe BlazeDS XML and XML External Entity Injection Vulnerabilities Source: XF Type: UNKNOWN adobe-xml-info-disclosure(56259) Source: CCN Type: NMAP Web site File http-coldfusion-subzero Source: CCN Type: NMAP Web site File http-vuln-cve2009-3960 Source: CCN Type: CYBERSECURITY & INFRASTRUCTURE SECURITY AGENCY KNOWN EXPLOITED VULNERABILITIES CATALOG Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [02-22-2010] Source: EXPLOIT-DB Type: UNKNOWN 41855 Source: CCN Type: Rapid7 Vulnerability and Exploit Database [05-30-2018] Adobe XML External Entity Injection | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |