Back
CVE-2005-4342
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."
Published: Dec 19, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (5)
| Vendor | Product | Version |
|---|---|---|
| macromedia | coldfusion | 6.0 |
| macromedia | coldfusion | 6.1 |
| macromedia | coldfusion | 6.1 |
| macromedia | coldfusion | 6.1 |
| macromedia | coldfusion | 7.0 |
GitHub Security Advisory GHSA-pgj6-vc56-h2jc
ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0...
References (12)
- http://secunia.com/advisories/18078 Patch, Vendor Advisory
- http://securitytracker.com/id?1015369 Patch, Vendor Advisory
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html Patch
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html Patch
- http://www.securityfocus.com/bid/15904 Patch
- http://www.vupen.com/english/advisories/2005/2948
- http://secunia.com/advisories/18078 Patch, Vendor Advisory
- http://securitytracker.com/id?1015369 Patch, Vendor Advisory
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-12.html Patch
- http://www.macromedia.com/devnet/security/security_zone/mpsb05-14.html Patch
- http://www.securityfocus.com/bid/15904 Patch
- http://www.vupen.com/english/advisories/2005/2948
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
1.70%
Top 25% most likely to be exploited
Threat Score
30.5 / 100
Data Sources
NVD
EPSS
GitHub