March 7, 2022 · Applied Cybernetics Group
CVE-2009-3960 — Adobe BlazeDS
known ransomware use
Adobe BlazeDS Information Disclosure Vulnerability
- Added to KEV
2022-03-07- Federal due date
2022-09-07- Vendor
- Adobe
- Product
- BlazeDS
- EPSS
- 99.8th percentile (score 0.900, as of
2026-09-16) - NVD CVSS v3.1
- 6.5 (MEDIUM)
- Ransomware use
- Known
- ATT&CK
- T1190 , T1486 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2009-3960
CISA short description
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Required action
Apply updates per vendor instructions.
NVD description
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.