First published: Thu May 16 2013(Updated: )
Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =9.0 | |
Adobe ColdFusion | =9.0-update_10 | |
Adobe ColdFusion | =9.0.1 | |
Adobe ColdFusion | =9.0.1-update_9 | |
Adobe ColdFusion | =9.0.2 | |
Adobe ColdFusion | =9.0.2-update_4 | |
Adobe ColdFusion | =10.0 | |
Adobe ColdFusion | =10.0-update1 | |
Adobe ColdFusion | =10.0-update3 | |
Adobe ColdFusion | =10.0-update4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1389 has a high severity level due to the potential for remote code execution.
To fix CVE-2013-1389, update Adobe ColdFusion to the latest version or apply the necessary patches as specified by Adobe.
CVE-2013-1389 affects Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10 before their respective updates.
CVE-2013-1389 can be exploited by remote attackers to execute arbitrary code on vulnerable systems.
Currently, the best approach for CVE-2013-1389 is to apply updates as no specific workaround is documented.