CVE-2005-4344: Low severity Macromedia ColdFusion vulnerability
Adobe (formerly Macromedia) ColdFusion MX 7.0 does not honor when the CFOBJECT /CreateObject(Java) setting is disabled, which allows local users to create an object despite the specified configuration.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4344?
CVE-2005-4344 is considered to have a moderate severity level due to potential unauthorized access to create objects.
How do I fix CVE-2005-4344?
To fix CVE-2005-4344, ensure that the CFOBJECT /CreateObject(Java) setting is fully enforced and consider updating to a newer version of ColdFusion.
What systems are affected by CVE-2005-4344?
CVE-2005-4344 specifically affects Adobe ColdFusion MX version 7.0.
What are the implications of CVE-2005-4344?
CVE-2005-4344 may allow local users to bypass security settings, potentially leading to unauthorized system access.
Is CVE-2005-4344 specific to any particular setup?
CVE-2005-4344 is particularly relevant in environments where Java object creation is restricted but not effectively enforced.