|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3960
The original article can be found at: http://www.securityfocus.com/bid/38197
|
| |
Vulnerable Systems:
* Adobe LiveCycle Data Services 2.6.1
* Adobe LiveCycle Data Services 2.5.1
* Adobe LiveCycle Data Services 3.0
* Adobe LiveCycle 8.2.1
* Adobe LiveCycle 8.0.1
* Adobe LiveCycle 9.0
* Adobe Flex Data Services 2.0.1
* Adobe ColdFusion 8.0.1
* Adobe ColdFusion 7.0.2
* Adobe ColdFusion 9.0
* Adobe ColdFusion 8.0
* Adobe ColdFusion 8
* Adobe BlazeDS 3.2
Adobe BlazeDS is prone to an XML-injection vulnerability and an XML External Entity injection vulnerability.
Attackers can exploit these issues to obtain sensitive information and carry out other attacks.
Vendor Status:
Adobe as issued an update for this vulnerablity.
Patch Availability:
http://www.adobe.com/
CVE Information:
CVE-2009-3960
|
|
|