CVE-2004-2331

ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*

History

20 Nov 2024, 23:53

Type Values Removed Values Added
References () http://secunia.com/advisories/10743/ - URL Repurposed () http://secunia.com/advisories/10743/ - URL Repurposed
References () http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html - Patch, Vendor Advisory () http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/9521 - Broken Link, Patch, Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/9521 - Broken Link, Patch, Third Party Advisory, VDB Entry
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - Third Party Advisory, VDB Entry

25 Jan 2024, 02:16

Type Values Removed Values Added
References (SECUNIA) http://secunia.com/advisories/10743/ - Patch, Vendor Advisory (SECUNIA) http://secunia.com/advisories/10743/ - URL Repurposed
References (BID) http://www.securityfocus.com/bid/9521 - Patch (BID) http://www.securityfocus.com/bid/9521 - Broken Link, Patch, Third Party Advisory, VDB Entry
References (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - (XF) https://exchange.xforce.ibmcloud.com/vulnerabilities/14984 - Third Party Advisory, VDB Entry
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
CWE NVD-CWE-Other CWE-470

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:53


NVD link : CVE-2004-2331

Mitre link : CVE-2004-2331

CVE.ORG link : CVE-2004-2331


JSON object : View

Products Affected

macromedia

  • coldfusion
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')