Monday, August 31, 2015

Adobe ColdFusion Hotfix Available

Adobe have released updated versions of ColdFusion web application development platform. This hotfix addresses an issue associated with the parsing of crafted XML external entities in BlazeDS that could lead to information disclosure (CVE-2015-3269).

Affected versions:
- ColdFusion 11 and 10


More information can be read from Adobe's security bulletin.

No comments: