Executive brief
Adobe ColdFusion 9.0 through 9.0.2 contains an authentication bypass vulnerability when a password is not configured. Remote attackers can exploit this to bypass authentication and potentially execute arbitrary code.
Affected products
- Adobe ColdFusion 9.0, 9.0.1, 9.0.2
Timeline
- 2013-01-08: disclosed: NVD Published Date
- 2013-01-01: exploited: Exploited in the wild in January 2013
- 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog