CVE-2013-0632: Adobe ColdFusion Authentication Bypass Vulnerability
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
Other sources
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0632?
CVE-2013-0632 has a high severity rating due to its potential to allow unauthorized administrative access to Adobe ColdFusion.
How can CVE-2013-0632 be fixed?
To fix CVE-2013-0632, Adobe suggests upgrading to a newer version of ColdFusion that addresses this vulnerability.
Which versions of Adobe ColdFusion are affected by CVE-2013-0632?
CVE-2013-0632 affects Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10.0.
What type of attack does CVE-2013-0632 enable?
CVE-2013-0632 enables remote attackers to bypass authentication and potentially execute arbitrary commands.
Is an update available for CVE-2013-0632?
Yes, Adobe has provided updates that address CVE-2013-0632 in their security notifications.