CVE-2013-0632

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 17, 2013
Updated: Dec 20, 2024
CWE ID 276

Summary

CVE-2013-0632 is a vulnerability in Adobe ColdFusion versions 9.0, 9.0.1, 9.0.2, and 10. An attacker can exploit this flaw by gaining unauthorized access to the RDS component using the default empty password. Successful exploitation allows the attacker to bypass authentication and potentially execute arbitrary code. This vulnerability was exploited in the wild in January 2013, highlighting its significance and the need for affected users to apply the available patch promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share