Monday, May 13, 2013

Unpatched Vulnerability In ColdFusion

Adobe has identified a critical vulnerability in its ColdFusion web application development platform. The vulnerability (CVE-2013-3336) could be exploited to gain access to files stored on vulnerable computers.

Affected versions are ColdFusion 10, 9.0.2, 9.0.0, 9.0 and older versions for Windows, Mac, and Unix. An exploit for the flaw is reportedly available. Adobe plans to release a patch for the vulnerability on May 14. More information in related security advisory.

No comments: