PT-2006-4824 · Adobe · Coldfusion Mx
Publicado
2006-08-09
·
Atualizado
2017-07-20
·
CVE-2006-3979
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ColdFusion MX version 7
Description
The issue allows attackers to bypass authentication by using programmatic access to the AdminAPI instead of the ColdFusion Administrator.
Recommendations
For ColdFusion MX version 7, consider disabling programmatic access to the AdminAPI as a temporary workaround until a patch is available. Restrict access to the AdminAPI to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Coldfusion Mx