LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2009-3960: Adobe BlazeDS Information Disclosure Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Sep 7, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2009-3960 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Sep 7, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

CVE-2009-3960 is an information disclosure vulnerability in Adobe BlazeDS, a component used in Adobe LifeCycle and ColdFusion products. An attacker who can reach an affected instance may be able to obtain sensitive data that the application should not expose.

This matters because BlazeDS often sits in application tiers that handle business data. Successful abuse can give an attacker material useful for further intrusion, and the vulnerability has been associated with known ransomware activity. Confirm exact product coverage and fixed builds against the vendor advisory.

How it works

Public detail on the precise weakness class (CWE) is limited. At a high level, the flaw allows unauthorized disclosure of information from the BlazeDS service when it is reachable by an attacker. In products that embed BlazeDS—such as LifeCycle and ColdFusion—this typically means a remote party can induce the component to return data it should keep internal.

Abuse generally involves sending crafted requests to the exposed BlazeDS endpoint so that the service responds with information beyond what an unauthenticated or unauthorized client should receive. Exact request format, parameters, and response contents are not specified here; treat any publicly reachable BlazeDS interface as in scope until you verify the vendor’s description and your configuration.

Am I affected? How to find it in your systems

BlazeDS appears in Adobe LifeCycle and ColdFusion deployments and may also be present in custom or third-party applications that bundle the library. Inventory steps:

Telemetry signs of exploitation are not detailed in the provided facts. Monitor for unusual or high-volume requests to BlazeDS-related paths, unexpected information-bearing responses, and follow-on access that could indicate use of disclosed data. Correlate with authentication and application logs where available.

How to remediate

Patch first. Apply the updates specified by Adobe for the affected BlazeDS, LifeCycle, and ColdFusion products, following the vendor’s instructions exactly. CISA’s required action is to apply updates per vendor instructions.

After patching:

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited vulnerabilities, including those tied to ransomware use, can lead to broader compromise once an attacker obtains internal information. If you believe an affected system was reachable and unpatched during a relevant window, treat it as a potential incident: preserve logs, assess what data the BlazeDS tier could have disclosed, and follow your incident-response process. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or identities appear in public breach sets, then force password resets and review access where warranted.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · BlazeDS
Added to CISA KEVMar 7, 2022
Federal patch deadlineSep 7, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities