Vulnerability CVE-2014-0570: Information

Description

Cross-site request forgery (CSRF) vulnerability in Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Severity: MEDIUM (6.8)

Published: Oct. 15, 2014
Modified: Sept. 4, 2020
Error type identifier: CWE-352

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
adobe-flash-playerp911-alt3432-alt1110ALT-PU-2014-2269-1132311Fixed
adobe-flash-playerc9f211-alt3432-alt117ALT-PU-2014-2269-1132311Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:adobe:coldfusion:9.0.1:update_9:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0.2:update_6:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:11.0:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0.2:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0:update_12:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0.1:update_11:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0.2:update_4:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:9.0:update_10:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update1:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update11:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update12:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update2:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update3:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update4:*:*:*:*:*:*

      cpe:2.3:a:adobe:coldfusion:10.0:update8:*:*:*:*:*:*