CVE-2012-0770: Medium severity adobe coldfusion vulnerability
Adobe ColdFusion 8.0, 8.0.1, 9.0, and 9.0.1 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0770?
CVE-2012-0770 is classified as a denial of service vulnerability due to the potential for high CPU consumption.
How do I fix CVE-2012-0770?
To fix CVE-2012-0770, update to a patched version of Adobe ColdFusion that addresses this vulnerability.
What versions of Adobe ColdFusion are affected by CVE-2012-0770?
CVE-2012-0770 affects Adobe ColdFusion versions 8.0, 8.0.1, 9.0, and 9.0.1.
What type of attack is enabled by CVE-2012-0770?
CVE-2012-0770 allows remote attackers to conduct denial of service attacks by exploiting hash collisions.
Can CVE-2012-0770 lead to data breaches?
While CVE-2012-0770 primarily leads to denial of service, it does not directly allow for unauthorized access to data.