First published: Sat Dec 17 2005(Updated: )
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4342 is considered a high severity vulnerability due to its potential to allow remote attackers to bypass security controls.
To fix CVE-2005-4342, ensure that the SecurityManager in ColdFusion is enabled and apply any available patches from Adobe.
CVE-2005-4342 affects ColdFusion MX 6.0, 6.1, and 7.0.
Yes, CVE-2005-4342 allows remote attackers to exploit the vulnerability if the SecurityManager is disabled.
The potential impacts of CVE-2005-4342 include unauthorized access and the ability to execute arbitrary code on the affected ColdFusion servers.