First published: Thu May 13 2010(Updated: )
Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =7.0.2 | |
Adobe ColdFusion | =8.0 | |
Adobe ColdFusion | =6.0 | |
Adobe ColdFusion | =7.0 | |
Adobe ColdFusion | =5.0 | |
Adobe ColdFusion | <=9.0 | |
Adobe ColdFusion | =7.2-unknown | |
Adobe ColdFusion | =6.1 | |
Adobe ColdFusion | =7.0.1 | |
Adobe ColdFusion | =8.0.1 | |
Adobe ColdFusion | =4.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-1294 has not been assigned an official CVSS score, but it is considered a serious local information disclosure vulnerability.
To mitigate CVE-2010-1294, users should upgrade Adobe ColdFusion to the latest version available.
CVE-2010-1294 affects Adobe ColdFusion versions 5.0 through 9.0, including specific subversions 8.0, 8.0.1, and 7.0.2.
No, CVE-2010-1294 is a local vulnerability, which means it requires local access to exploit.
CVE-2010-1294 could allow local users to access sensitive information, although the specifics of the information are not detailed.