PT-2013-1384 · Adobe · Coldfusion

Richard Brain

·

Published

2013-09-20

·

Updated

2017-08-29

·

CVE-2010-5290

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions prior to 10
Description The authentication process in Adobe ColdFusion does not require knowledge of the cleartext password if the password hash is known. This makes it easier for attackers to obtain administrative privileges by leveraging read access to the configuration file.
Recommendations For versions prior to 10, update to version 10 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-5290

Affected Products

Coldfusion