First published: Wed Jan 09 2013(Updated: )
Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | ||
Adobe ColdFusion | =9.0 | |
Adobe ColdFusion | =9.0.1 | |
Adobe ColdFusion | =9.0.2 | |
Adobe ColdFusion | =10.0 | |
All of | ||
Any of | ||
Adobe ColdFusion | =9.0 | |
Adobe ColdFusion | =9.0.1 | |
Adobe ColdFusion | =9.0.2 | |
Adobe ColdFusion | =10.0 | |
Any of | ||
Apple iOS and macOS | ||
Microsoft Windows | ||
opengroup Unix |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0629 is considered a critical vulnerability due to its potential for unauthorized access to restricted directories.
To fix CVE-2013-0629, ensure that strong passwords are configured for all ColdFusion installations.
CVE-2013-0629 affects Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10.0.
CVE-2013-0629 is a directory traversal vulnerability that can allow attackers access to restricted directories.
Yes, CVE-2013-0629 can be exploited remotely when proper password protections are not configured.