CVE-2004-1815: Medium severity Macromedia ColdFusion vulnerability
Published Mar 15, 2004
·Updated
Unknown vulnerability in ColdFusion MX 6.0 and 6.1, and JRun 4.0, when a SOAP web service expects an array of objects as an argument, allows remote attackers to cause a denial of service (memory consumption).
Affected Software
12 affected components
Macromedia ColdFusion=6.0
Macromedia ColdFusion=6.1
Macromedia JRun=4.0
Macromedia JRun=4.0-sp1
Macromedia JRun=4.0-sp1a
Macromedia JRun=4.0_build_61650
Sun ONE Application Server=7.0
Sun ONE Application Server=7.0
Sun ONE Application Server=7.0-ur1
Sun ONE Application Server=7.0-ur1
Sun ONE Application Server=7.0-ur2
Sun ONE Application Server=7.0-ur2
Remediation
Patch Available
Patch Available
Event History
Mar 15, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1815?
CVE-2004-1815 is considered a denial of service vulnerability due to excessive memory consumption.
2
How do I fix CVE-2004-1815?
To mitigate CVE-2004-1815, it is recommended to upgrade to a patched version of ColdFusion MX or JRun.
3
Which software is affected by CVE-2004-1815?
CVE-2004-1815 affects ColdFusion MX 6.0, 6.1 and JRun 4.0.
4
Can CVE-2004-1815 be exploited remotely?
Yes, CVE-2004-1815 can be exploited remotely by attackers through SOAP web services.
5
What type of attack does CVE-2004-1815 facilitate?
CVE-2004-1815 facilitates denial of service attacks due to high memory consumption.