PT-2006-4824 · Adobe · Coldfusion Mx
Published
2006-08-09
·
Updated
2017-07-20
·
CVE-2006-3979
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ColdFusion MX version 7
Description
The issue allows attackers to bypass authentication by using programmatic access to the AdminAPI instead of the ColdFusion Administrator.
Recommendations
For ColdFusion MX version 7, consider disabling programmatic access to the AdminAPI as a temporary workaround until a patch is available. Restrict access to the AdminAPI to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion Mx