Back

CVE-2005-4342

ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0 does not throw an exception if the SecurityManager is disabled, which might allow remote attackers to "bypass security controls," aka "JRun Clustered Sandbox Security Vulnerability."

Published: Dec 19, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
macromedia coldfusion 6.0
macromedia coldfusion 6.1
macromedia coldfusion 6.1
macromedia coldfusion 6.1
macromedia coldfusion 7.0

GitHub Security Advisory GHSA-pgj6-vc56-h2jc

ColdFusion Sandbox on Adobe (formerly Macromedia) ColdFusion MX 6.0, 6.1, 6.1 with JRun, and 7.0...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 1.70%

Top 25% most likely to be exploited

Threat Score 30.5 / 100

Data Sources

NVD EPSS GitHub