CVE-2004-2331

ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
References
Link Resource
http://secunia.com/advisories/10743/ URL Repurposed
http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html Patch Vendor Advisory
http://www.securityfocus.com/bid/9521 Broken Link Patch Third Party Advisory VDB Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*

History

25 Jan 2024, 02:16

Type Values Removed Values Added
References () http://secunia.com/advisories/10743/ - Patch, Vendor Advisory () http://secunia.com/advisories/10743/ - URL Repurposed
References () http://www.securityfocus.com/bid/9521 - Patch () http://www.securityfocus.com/bid/9521 - Broken Link, Patch, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - Third Party Advisory, VDB Entry
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
CWE NVD-CWE-Other CWE-470

Information

Published : 2004-12-31 05:00

Updated : 2024-01-25 02:16


NVD link : CVE-2004-2331

Mitre link : CVE-2004-2331

CVE.ORG link : CVE-2004-2331


JSON object : View

Products Affected

macromedia

  • coldfusion
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')