ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2005-08-16T04:00:00
Updated: 2024-08-08T01:22:13.663Z
Reserved: 2005-08-16T00:00:00
Link: CVE-2004-2331
Vulnrichment
No data.
NVD
Status : Modified
Published: 2004-12-31T05:00:00.000
Modified: 2024-11-20T23:53:04.967
Link: CVE-2004-2331
Redhat
No data.