Adobe warns customers of unpatched critical flaw in ColdFusion

There are reports that a public exploit is already available for this vulnerability, Adobe said

Adobe has warned users of its ColdFusion application server platform of a critical vulnerability that could give unauthorized users access to sensitive files stored on their servers.

The vulnerability is identified as CVE-2013-3336 and affects ColdFusion 10, 9.0.2, 9.0.1, 9.0 and earlier versions for Windows, Macintosh and UNIX, Adobe said in an advisory published Wednesday.

The company credited Marcin Siedlarz of Symantec's Security Response team with reporting the issue. "There are reports that an exploit for this vulnerability is publicly available," Adobe said.

The company is working on a fix and expects to release it publicly on May 14. Until then, customers are advised to restrict public access to certain sensitive directories like CFIDE/administrator, CFIDE/adminapi and CFIDE/gettingstarted.

Information on how to restrict access to these directories is provided in the ColdFusion 9 Lockdown Guide and ColdFusion 10 Lockdown Guide. Customers who hardened their ColdFusion installations following the guidance provided in these technical documents are already protected against CVE-2013-3336, Adobe said.

Even though it's not as widely used as some other Adobe products, ColdFusion has been targeted by hackers in the past. In April, virtual private server hosting company Linode reported that hackers gained access to its Web server and customer database by exploiting a previously unknown ColdFusion vulnerability.

In January, Adobe issued a security advisory warning customers about four previously unknown ColdFusion vulnerabilities that were being actively exploited by attackers. The mitigation steps recommended at the time also involved disabling external access to the /CFIDE/administrator and /CFIDE/adminapi directories.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags adobesymantecAccess control and authenticationExploits / vulnerabilitiesLinode

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?