CVE-2011-0584: Medium severity adobe coldfusion vulnerability
Published Feb 10, 2011
·Updated
Session fixation vulnerability in Adobe ColdFusion 8.0 through 9.0.1 allows remote attackers to hijack web sessions via unspecified vectors.
Affected Software
4 affected components
Adobe ColdFusion=8.0
Adobe ColdFusion=9.0
Adobe ColdFusion=8.0.1
Adobe ColdFusion=9.0.1
Remediation
Event History
Feb 10, 2011
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-0584?
CVE-2011-0584 is considered a medium severity vulnerability due to the risk of session hijacking.
2
How do I fix CVE-2011-0584?
To fix CVE-2011-0584, update Adobe ColdFusion to version 9.0.2 or later.
3
What types of attacks are possible with CVE-2011-0584?
CVE-2011-0584 allows remote attackers to hijack web sessions through session fixation techniques.
4
Which versions of Adobe ColdFusion are affected by CVE-2011-0584?
CVE-2011-0584 affects Adobe ColdFusion versions 8.0, 8.0.1, 9.0, and 9.0.1.
5
Is there a workaround for CVE-2011-0584?
There is no official workaround for CVE-2011-0584; updating to a patched version is recommended.