First published: Wed Jul 10 2013(Updated: )
Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =10.0 | |
Adobe ColdFusion | =10.0-update1 | |
Adobe ColdFusion | =10.0-update2 | |
Adobe ColdFusion | =10.0-update3 | |
Adobe ColdFusion | =10.0-update4 | |
Adobe ColdFusion | =10.0-update8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3350 has been classified as a medium severity vulnerability due to the potential for unauthorized access to ColdFusion Components.
To fix CVE-2013-3350, update Adobe ColdFusion to version 10.0 Update 11 or later.
The potential impacts of CVE-2013-3350 include unauthorized execution of public methods in ColdFusion Components via WebSockets.
CVE-2013-3350 affects Adobe ColdFusion 10.0 and its updates up to 10.0-update8.
Yes, CVE-2013-3350 allows remote attackers to exploit WebSockets to invoke public methods on ColdFusion Components.