---
id: CVE-2009-3960
title: >-
  Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle
  8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex
  Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote
  attackers…
summary: >-
  Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle
  8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex
  Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote
  attackers…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
vendor: adobe
product: blazeds
affected:
  - blazeds <= 3.2
  - coldfusion = 7.0.2
  - coldfusion = 8.0
  - coldfusion = 8.0.1
  - coldfusion = 9.0
  - flex_data_services = 2.0.1
  - livecycle = 8.0.1
  - livecycle = 8.2.1
  - livecycle = 9.0
  - livecycle_data_services = 2.5.1
  - livecycle_data_services = 2.6.1
  - livecycle_data_services = 3.0
published: '2010-02-15'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2009-3960'
references:
  - url: 'http://secunia.com/advisories/38543'
    label: psirt@adobe.com
  - url: 'http://securitytracker.com/id?1023584'
    label: psirt@adobe.com
  - url: 'http://www.adobe.com/support/security/bulletins/apsb10-05.html'
    label: psirt@adobe.com
  - url: 'http://www.osvdb.org/62292'
    label: psirt@adobe.com
  - url: 'http://www.securityfocus.com/bid/38197'
    label: psirt@adobe.com
  - url: 'https://www.exploit-db.com/exploits/41855/'
    label: psirt@adobe.com
  - url: 'http://secunia.com/advisories/38543'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://securitytracker.com/id?1023584'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.adobe.com/support/security/bulletins/apsb10-05.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.osvdb.org/62292'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/38197'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.exploit-db.com/exploits/41855/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.90012
epssPercentile: 0.99788
kev: true
kevDateAdded: '2022-03-07'
kevDueDate: '2022-09-07'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-01T06:11:30.660Z'
exploits:
  exploitdb: true
  metasploit:
    - auxiliary/scanner/http/adobe_xml_inject
  checkedAt: '2026-09-23T07:13:14.752Z'
---

## Overview

Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

## Affected

- `blazeds <= 3.2`
- `coldfusion = 7.0.2`
- `coldfusion = 8.0`
- `coldfusion = 8.0.1`
- `coldfusion = 9.0`
- `flex_data_services = 2.0.1`
- `livecycle = 8.0.1`
- `livecycle = 8.2.1`
- `livecycle = 9.0`
- `livecycle_data_services = 2.5.1`
- `livecycle_data_services = 2.6.1`
- `livecycle_data_services = 3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
