CVE Vulnerabilities

CVE-2013-0625

Improper Authentication

Published: Jan 09, 2013 | Modified: Dec 20, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Coldfusion Adobe 9.0 (including) 9.0 (including)
Coldfusion Adobe 9.0.1 (including) 9.0.1 (including)
Coldfusion Adobe 9.0.2 (including) 9.0.2 (including)

Potential Mitigations

References