CVE Vulnerabilities

CVE-2010-5290

Published: Sep 20, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861.

Affected Software

NameVendorStart VersionEnd Version
ColdfusionAdobe*9.0.2 (including)
ColdfusionAdobe9.0 (including)9.0 (including)
ColdfusionAdobe9.0.1 (including)9.0.1 (including)

References