#VU45343 Input validation error in ColdFusion - CVE-2011-0582


| Updated: 2020-08-11

Vulnerability identifier: #VU45343

Vulnerability risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2011-0582

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
ColdFusion
Server applications / Application servers

Vendor: Adobe

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Unspecified vulnerability in the administrator console in Adobe ColdFusion 8.0 through 9.0.1 allows attackers to obtain sensitive information via unknown vectors.

Mitigation
Install update from vendor's website.

Vulnerable software versions

ColdFusion: 8.0 - 8.0.1, 9.0 - 9.0.1


External links
https://secunia.com/advisories/43264
https://www.adobe.com/support/security/bulletins/apsb11-04.html
https://www.securityfocus.com/bid/46274
https://www.securitytracker.com/id?1025036
https://www.vupen.com/english/advisories/2011/0334
https://exchange.xforce.ibmcloud.com/vulnerabilities/65278


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability