CVE Vulnerabilities

CVE-2009-3960

Published: Feb 15, 2010 | Modified: Aug 16, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

Affected Software

Name Vendor Start Version End Version
Blazeds Adobe * 3.2 (including)
Coldfusion Adobe 7.0.2 (including) 7.0.2 (including)
Coldfusion Adobe 8.0 (including) 8.0 (including)
Coldfusion Adobe 8.0.1 (including) 8.0.1 (including)
Coldfusion Adobe 9.0 (including) 9.0 (including)
Flex_data_services Adobe 2.0.1 (including) 2.0.1 (including)
Lifecycle Adobe 8.0.1 (including) 8.0.1 (including)
Lifecycle Adobe 8.2.1 (including) 8.2.1 (including)
Lifecycle Adobe 9.0 (including) 9.0 (including)
Lifecycle_data_services Adobe 2.5.1 (including) 2.5.1 (including)
Lifecycle_data_services Adobe 2.6.1 (including) 2.6.1 (including)
Lifecycle_data_services Adobe 3.0 (including) 3.0 (including)

References