|
Comments
|
Today's Top SOA Links
Security Hotfixes Now Available for ColdFusion and JRun
Adobe patches critical vulnerabilities in ColdFusion v8.0.1 (and earlier versions) and JRun 4.0.
Aug. 20, 2009 11:45 AM
Critical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. Adobe has now patched them with a Security Update released on August 17, 2009. "SummaryCritical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system. Affected software versionsColdFusion 8.0.1 and earlier versions SolutionAdobe recommends affected ColdFusion and JRun customers update their installations using the links in the Details section below. Severity ratingAdobe categorizes these as critical issues and recommends affected users patch their installations. DetailsCritical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system. An update for ColdFusion resolves a cross-site scripting vulnerability that could potentially lead to code execution (CVE-2009-1872). An update for ColdFusion resolves a cross-site scripting vulnerability that could potentially lead to code execution (CVE-2009-1877). ColdFusion users can find the appropriate links to fix CVE-2009-1872 and CVE-2009-1877 here: An update for JRun resolves a management console directory traversal vulnerability that could potentially lead to information disclosure (CVE-2009-1873). An update for JRun resolves multiple management console cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1874). JRun users can find the appropriate links to fix CVE-2009-1873 and CVE-2009-1874 here: An update for ColdFusion resolves multiple cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1875). ColdFusion users can find the appropriate links to fix CVE-2009-1875 here: An update for ColdFusion resolves a double-encoded null character vulnerability that could potentially lead to information disclosure (CVE-2009-1876). ColdFusion users can find the appropriate links to fix CVE-2009-1876 here: An update for ColdFusion resolves a session fixation vulnerability that could potentially lead to privilege escalation (CVE-2009-1878). ColdFusion users can find the appropriate links to fix CVE-2009-1878 here: AcknowledgmentsAdobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers’ security.
Reader Feedback: Page 1 of 1
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
|
SYS-CON Featured Whitepapers
Most Read This Week |
|||||||||||||||||||||||||||