ZeroHour

CVE-2009-3960

KEV ransomwarelarge

Information Disclosure in Adobe BlazeDS (Used by LiveCycle and ColdFusion)

CISA: Adobe BlazeDS Information Disclosure Vulnerability

CVSS
EPSS
90%p100
Published
KEV added
AI analysis

CVE-2009-3960 is an information disclosure vulnerability in Adobe BlazeDS, the Java-based remoting and messaging layer that ships with Adobe LiveCycle and is available with Adobe ColdFusion. An attacker can trigger the flaw by sending crafted requests to an application running an affected BlazeDS deployment, gaining access to information that should not be exposed. Successful exploitation can leak sensitive data and, as observed in the Cring ransomware campaign against unpatched ColdFusion servers, can serve as an initial foothold that leads to further compromise and ransomware deployment. Organizations running BlazeDS as part of LiveCycle or ColdFusion deployments are affected. The flaw has been exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, with ransomware use explicitly confirmed and a very high EPSS of 90%.

What to do: Apply updates per vendor instructions as required by CISA, upgrading BlazeDS, LiveCycle, and ColdFusion to the patched releases specified in Adobe's advisory. Prioritize internet-facing ColdFusion and LiveCycle servers, verify BlazeDS-related endpoints are patched, and check for signs of compromise given known ransomware use. Until patched, restrict external access to BlazeDS/ColdFusion endpoints where feasible.

Affected
Adobe BlazeDS (as used in LiveCycle and ColdFusion)
Estimated exposure
largeon the order of tens of thousands of internet-exposed ColdFusion/LiveCycle servers plausibly affected — BlazeDS is bundled with Adobe ColdFusion and LiveCycle deployments, and public internet scans have historically shown tens of thousands of exposed Adobe ColdFusion servers, so the estimate assumes a similar magnitude; the exact count of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.

CISA Known Exploited Vulnerability
Affected
Adobe BlazeDS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Adobe
Products
BlazeDS

In the news