Lucene search

K
nvd[email protected]NVD:CVE-2005-4342
HistoryDec 19, 2005 - 3:47 a.m.

CVE-2005-4342

2005-12-1903:47:00
web.nvd.nist.gov
2

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

80.8%

ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to “bypass security controls,” aka “JRun Clustered Sandbox Security Vulnerability.”

Affected configurations

Nvd
Node
macromediacoldfusionMatch6.0
OR
macromediacoldfusionMatch6.1
OR
macromediacoldfusionMatch6.1enterprise_with_jrun
OR
macromediacoldfusionMatch6.1j2ee_application_server
OR
macromediacoldfusionMatch7.0
VendorProductVersionCPE
macromediacoldfusion6.0cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*
macromediacoldfusion6.1cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
macromediacoldfusion6.1cpe:2.3:a:macromedia:coldfusion:6.1:*:enterprise_with_jrun:*:*:*:*:*
macromediacoldfusion6.1cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*
macromediacoldfusion7.0cpe:2.3:a:macromedia:coldfusion:7.0:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.7

Confidence

Low

EPSS

0.007

Percentile

80.8%

Related for NVD:CVE-2005-4342