CVE-2012-5675: Medium severity adobe coldfusion vulnerability
Published Dec 12, 2012
·Updated
Adobe ColdFusion 9.0 through 9.0.2, and 10, allows local users to bypass intended shared-hosting sandbox permissions via unspecified vectors.
Affected Software
4 affected components
Adobe ColdFusion=9.0
Adobe ColdFusion=9.0.1
Adobe ColdFusion=9.0.2
Adobe ColdFusion=10.0
Remediation
Event History
Dec 12, 2012
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-5675?
CVE-2012-5675 has a high severity rating as it allows local users to bypass sandbox permissions.
2
How do I fix CVE-2012-5675?
To fix CVE-2012-5675, you should update to the latest version of Adobe ColdFusion, specifically versions beyond 9.0.2 and 10.0.
3
Which versions of Adobe ColdFusion are affected by CVE-2012-5675?
CVE-2012-5675 affects Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10.0.
4
What vulnerabilities does CVE-2012-5675 exploit?
CVE-2012-5675 exploits unspecified vectors to bypass intended shared-hosting sandbox permissions.
5
Is there a workaround for CVE-2012-5675?
No specific workaround has been documented for CVE-2012-5675; updating Adobe ColdFusion is the recommended course of action.