Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 9.0 (including) | 9.0 (including) |
Coldfusion | Adobe | 9.0.1 (including) | 9.0.1 (including) |
Coldfusion | Adobe | 9.0.2 (including) | 9.0.2 (including) |