7.5
CWE
264
Advisory Published
Updated

CVE-2008-1656

First published: Wed Apr 09 2008(Updated: )

Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these methods via Flex 2 remoting, a different vulnerability than CVE-2006-4725.

Credit: cve@mitre.org

Affected SoftwareAffected VersionHow to fix
Adobe ColdFusion=8.0
Adobe ColdFusion=8.1

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2008-1656?

    CVE-2008-1656 has a medium severity rating due to the ability of remote attackers to invoke CFC methods.

  • How do I fix CVE-2008-1656?

    To fix CVE-2008-1656, update Adobe ColdFusion to version 8.0.1 or later.

  • What versions of Adobe ColdFusion are affected by CVE-2008-1656?

    Adobe ColdFusion versions 8.0 and 8.0.1 are affected by CVE-2008-1656.

  • Can CVE-2008-1656 be exploited remotely?

    Yes, CVE-2008-1656 can be exploited remotely through Flex 2 remoting.

  • Is there a workaround for CVE-2008-1656?

    There are no official workarounds for CVE-2008-1656; updating is the recommended action.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203