There is a Security update available for BlazeDS. ColdFusion 9.0, 8.0.x and 7.0.2 are also affected by this issue, and this technote provides fixes for the security issue along with the installation instructions.