First published: Tue Jul 19 2005(Updated: )
Race condition in Macromedia JRun 4.0, ColdFusion MX 6.1 and 7.0, when under heavy load, causes JRun to assign a duplicate authentication token to multiple sessions, which could allow authenticated users to gain privileges as other users.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0 | |
Adobe JRun | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2306 is considered to be a high severity vulnerability due to its potential to allow unauthorized access to user sessions.
To fix CVE-2005-2306, users should apply the latest patches provided by Adobe for ColdFusion 6.1, 7.0, and JRun 4.0.
CVE-2005-2306 affects Macromedia ColdFusion 6.1, ColdFusion 7.0, and JRun 4.0.
CVE-2005-2306 is a race condition vulnerability that can lead to improper session management.
Authenticated users are impacted by CVE-2005-2306 as it allows them to gain unauthorized privileges in other user sessions.