Skip to main content

Adobe ColdFusion Multiple Vulnerabilities

Last Update Date: 16 Oct 2014 Release Date: 15 Oct 2014 3705 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Several vulnerabilities were identified in Adobe ColdFusion.

  • A local user can bypass access control restrictions.
  • A remote user can conduct cross-site scripting attacks.
  • A remote user can conduct cross-site request forgery attacks.

Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  •  Versions 9.0, 9.0.1, 9.0.2, 10, 11

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply update.

Vulnerability Identifier


Source


Related Link