Evidence used
- CISA confirms exploitation in the wild.
- A structured source references public exploit or proof-of-concept material.
- EPSS is 90.12% for the current model date.
BlackTreeCVE IntelligenceAdobe · BlazeDS
CISA confirms exploitation in the wild and lists 2022-09-07 as the remediation due date.
CISA confirms exploitation in the wild and lists 2022-09-07 as the remediation due date.
Fix not verifiedAdobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.
An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may obtain information outside the intended access boundary.
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
The current structured CVE record identifies a security weakness, but the root cause requires confirmation in the linked vendor material.
An attacker operating through a network path may attempt exploitation without authentication after a user interaction. If successful, the issue may obtain information outside the intended access boundary.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2022-03-07. Known ransomware campaign use is recorded.
A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Published 15 Feb 2010 · Last source change 6 Aug 2026, 03:55 UTC · CWE not yet assigned
Missing structured fields: CWE classification. Missing data is not evidence of low risk; review the primary advisory.