CVE-2010-0185: Medium severity Adobe ColdFusion vulnerability
Published Feb 3, 2010
·Updated
The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.
Affected Software
1 affected component
Adobe ColdFusion=9.0
Event History
Feb 3, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-0185?
CVE-2010-0185 has a medium severity level, allowing potential data exposure.
2
How do I fix CVE-2010-0185?
To fix CVE-2010-0185, you should update Adobe ColdFusion to the latest version that addresses the vulnerability.
3
What types of data are exposed in CVE-2010-0185?
CVE-2010-0185 can expose collection metadata, search information, and index data.
4
Can CVE-2010-0185 be exploited remotely?
Yes, CVE-2010-0185 can be exploited by remote attackers without authentication.
5
Which version of Adobe ColdFusion is affected by CVE-2010-0185?
CVE-2010-0185 specifically affects Adobe ColdFusion version 9.0.