Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-0625

Overview

Vulnerability Score 6.8 6.8
CVE Id CVE-2013-0625
Last Modified 17 Jan 2013 11:50:10
Published 08 Jan 2013 08:55:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2013-0625

Summary

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

Vulnerable Systems

Application

  • Adobe Coldfusion 10.0

  • Adobe Coldfusion 9.0

  • Adobe Coldfusion 9.0.1

  • Adobe Coldfusion 9.0.2


References

CONFIRM - http://www.adobe.com/support/security/advisories/apsa13-01.html

BID - 57164

CONFIRM - http://www.adobe.com/support/security/bulletins/apsb13-03.html


Last Updated: 27 May 2016 11:01:34