VYPR
Unrated severityNVD Advisory· Published Dec 19, 2005· Updated Apr 16, 2026

CVE-2005-4342

CVE-2005-4342

Description

ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."

Affected products

5
  • cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:macromedia:coldfusion:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:macromedia:coldfusion:6.1:*:enterprise_with_jrun:*:*:*:*:*
    • cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*
    • cpe:2.3:a:macromedia:coldfusion:7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.