|
|
Info |
Last Modified |
| 11 months ago |
|
|
|
|
Description |
Macromedia ColdFusion MX and Macromedia ColdFusion MX J2EE contains a flaw that may allow a malicious local user to bypass the sandbox restrictions. The issue is triggered when creating Java objects without using CreateObject() or <cfobject> even if these features are disabled occurs. It is possible that the flaw may allow local users to bypass the sandbox restrictions.
|
|
Classification |
Location:
Local Access Required
Exploit:
Exploit Unknown
|
|
Technical |
ColdFusion MX 6.1 sandbox security can be compromised by creating Java objects without using CreateObject() or <cfobject> even if these features are disabled. The sandbox cannot be compromised externally, but programmers operating in a shared, hosted environment could be vulnerable.
|
|
Solution |
Currently, there are no known workarounds or upgrades to correct this issue. However, Macromedia has released a patch to address this vulnerability.
|
|
Products |
|
ColdFusion MX Enterprise
 |
6.1 |
ColdFusion MX J2EE
 |
All Versions |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|