Loading
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Use Adobe vendor hub and Blazeds product page to widen CVE-2009-3960 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2011-2092 and CVE-2011-2093 for nearby disclosures in the same product family.