Permissions, Privileges, and Access Controls in ColdFusion - CVE-2014-0572
Published: October 15, 2014 / Updated: August 10, 2020
ColdFusion
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.