CVE-2010-0185

The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.
Configurations

Configuration 1 (hide)

cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 01:11

Type Values Removed Values Added
References () http://kb2.adobe.com/cps/807/cpsid_80719.html - () http://kb2.adobe.com/cps/807/cpsid_80719.html -
References () http://osvdb.org/62037 - () http://osvdb.org/62037 -
References () http://secunia.com/advisories/38387 - Vendor Advisory () http://secunia.com/advisories/38387 - Vendor Advisory
References () http://www.adobe.com/support/security/bulletins/apsb10-04.html - Vendor Advisory () http://www.adobe.com/support/security/bulletins/apsb10-04.html - Vendor Advisory
References () http://www.securityfocus.com/bid/38007 - () http://www.securityfocus.com/bid/38007 -
References () http://www.securitytracker.com/id?1023519 - () http://www.securitytracker.com/id?1023519 -
References () http://www.vupen.com/english/advisories/2010/0259 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/0259 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/55997 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/55997 -

Information

Published : 2010-02-03 18:30

Updated : 2024-11-21 01:11


NVD link : CVE-2010-0185

Mitre link : CVE-2010-0185

CVE.ORG link : CVE-2010-0185


JSON object : View

Products Affected

adobe

  • coldfusion
CWE
CWE-264

Permissions, Privileges, and Access Controls