CVE-2004-2331
MEDIUMColdFusion MX 6.1-6.1 - Info Disclosure
Title source: llmDescription
ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.
References (4)
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
1.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-470
Status
draft
Affected Products (2)
macromedia/coldfusion
macromedia/coldfusion
Timeline
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026