First published: Fri Dec 31 2004(Updated: )
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2331 is considered a medium severity vulnerability due to its ability to allow local users to bypass security restrictions.
CVE-2004-2331 exploits ColdFusion's security by allowing users to use Java reflection methods to access trusted Java objects without proper authorization.
CVE-2004-2331 affects local users of Macromedia ColdFusion MX version 6.1 and 6.1 J2EE application servers.
CVE-2004-2331 poses risks of sensitive information exposure, as it allows unauthorized access to trusted Java objects.
To mitigate the risks associated with CVE-2004-2331, it is recommended to update ColdFusion to a more recent version that addresses this vulnerability.