CVE-2004-2331

ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*

History

No history.

Information

Published : 2004-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2004-2331

Mitre link : CVE-2004-2331

CVE.ORG link : CVE-2004-2331


JSON object : View

Products Affected

macromedia

  • coldfusion
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')