Adobe ColdFusion 9.0, 9.0.1 및 9.0.2는 암호가 구성되지 않은 경우 원격 공격자가 명시되지 않은 벡터를 통해 인증을 우회하고 임의 코드를 실행할 가능성이 있으며, 2013년 1월 실제 환경에서 악용되었습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.