Adobe security hotfixes for ColdFusion and JRun

Critical vulnerabilities have been identified in ColdFusion 8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system.

An update for ColdFusion resolves a cross-site scripting vulnerability that could potentially lead to code execution (CVE-2009-1872 and CVE-2009-1877). ColdFusion users can find the appropriate links to fix CVE-2009-1872 and CVE-2009-1877 here:

An update for JRun resolves a management console directory traversal vulnerability that could potentially lead to information disclosure (CVE-2009-1873). Another update for JRun resolves multiple management console cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1874).

JRun users can find the appropriate links to fix CVE-2009-1873 and CVE-2009-1874 here:

An update for ColdFusion resolves multiple cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1875).

ColdFusion users can find the appropriate links to fix CVE-2009-1875 here:

  • Installation instructions for CVE-2009-1875
  • CVE-2009-1875 Hotfix for ColdFusion 7.0.2
  • CVE-2009-1875 Hotfix for ColdFusion 8
  • CVE-2009-1875 Hotfix for ColdFusion 8.0.1
  • An update for ColdFusion resolves a double-encoded null character vulnerability that could potentially lead to information disclosure (CVE-2009-1876).

    ColdFusion users can find the appropriate links to fix CVE-2009-1876 here:

    An update for ColdFusion resolves a session fixation vulnerability that could potentially lead to privilege escalation (CVE-2009-1878).

    ColdFusion users can find the appropriate links to fix CVE-2009-1878 here:

    Don't miss