{
  "id": "CVE-2009-3960",
  "url": "https://spydr.io/cve/CVE-2009-3960",
  "published": "2010-02-15T18:30:00.407Z",
  "modified": "2026-08-06T05:16:33.473Z",
  "score": 6.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
  "score_source": "NVD",
  "epss": 0.90118,
  "epss_percentile": 0.99796,
  "exploited": true,
  "kev": {
    "added": "2022-03-07",
    "due": "2022-09-07",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Known",
    "name": "Adobe BlazeDS Information Disclosure Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2009-3960"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "adobe"
  ],
  "products": [
    "adobe blazeds",
    "adobe coldfusion",
    "adobe flex data services",
    "adobe livecycle",
    "adobe livecycle data services"
  ],
  "cwes": [],
  "description": "Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 6.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://secunia.com/advisories/38543",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://securitytracker.com/id?1023584",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.adobe.com/support/security/bulletins/apsb10-05.html",
      "tags": [
        "Not Applicable",
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://www.osvdb.org/62292",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/38197",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/41855/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2009-3960",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2009-3960",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
