HIGH
The authentication process in Adobe ColdFusion before 10 does not require knowledge of the cleartext password if the password hash is known, which makes it easier for context-dependent attackers to obtain administrative privileges by leveraging read access to the configuration file, a different vulnerability than CVE-2010-2861
Published Sep 20, 2013
10.0
HIGHCVSS 2.0
EPSS 5.53%
Description
Affected products
Remediation
Metrics
References (4)
Change history (0)
No recorded changes yet.