CVE-2004-2331

ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
References
Link Resource
http://secunia.com/advisories/10743/ URL Repurposed
http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html Patch Vendor Advisory
http://www.securityfocus.com/bid/9521 Broken Link Patch Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*

History

No history.

Information

Published : 2004-12-31 05:00

Updated : 2024-01-25 02:16


NVD link : CVE-2004-2331

Mitre link : CVE-2004-2331

CVE.ORG link : CVE-2004-2331


JSON object : View

Products Affected

macromedia

  • coldfusion
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')