CVE-2005-1022: Medium severity Macromedia ColdFusion vulnerability
Published Apr 9, 2005
·Updated
ColdFusion 6.1 Updater 1 places Java .class files under the web root in the /WEB-INF/cfclasses directory, which allows remote attackers to obtain sensitive information.
Affected Software
1 affected component
Macromedia ColdFusion=6.1
Remediation
Event History
Apr 9, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1022?
CVE-2005-1022 has a medium severity rating as it allows remote attackers to obtain sensitive information.
2
How do I fix CVE-2005-1022?
To fix CVE-2005-1022, ensure that sensitive Java class files are not publicly accessible and consider upgrading to a more secure version of ColdFusion.
3
What software versions are affected by CVE-2005-1022?
CVE-2005-1022 affects Macromedia ColdFusion version 6.1.
4
What type of information can be exposed due to CVE-2005-1022?
CVE-2005-1022 can expose sensitive Java .class files to unauthorized users.
5
Is there a workaround for CVE-2005-1022?
A potential workaround for CVE-2005-1022 includes configuring server settings to restrict access to the /WEB-INF/cfclasses directory.