{"api_version":"1","generated_at":"2026-07-23T07:36:18+00:00","cve":"CVE-2004-2331","urls":{"html":"https://cve.report/CVE-2004-2331","api":"https://cve.report/api/cve/CVE-2004-2331.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-2331","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-2331"},"summary":{"title":"CVE-2004-2331","description":"ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.","state":"PUBLISHED","assigner":"mitre","published_at":"2004-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-470","n/a"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14984","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html","name":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Macromedia - MPSB04-01 Security Patch available for ColdFusion MX sandbox security","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/9521","name":"http://www.securityfocus.com/bid/9521","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory","VDB Entry"],"title":"Macromedia ColdFusion MX Security Sandbox Circumvention Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/10743/","name":"http://secunia.com/advisories/10743/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"Secunia - Advisories - Cold Fusion MX Form Denial of Service and Sandbox Bypass","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-2331","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-2331","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"2331","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"coldfusion","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"2331","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macromedia","cpe5":"coldfusion","cpe6":"6.1","cpe7":"*","cpe8":"j2ee_application_server","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:22:13.663Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html"},{"name":"coldfusion-mx-sandbox-bypass(14984)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14984"},{"name":"9521","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/9521"},{"name":"10743","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/10743/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-01-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html"},{"name":"coldfusion-mx-sandbox-bypass(14984)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14984"},{"name":"9521","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/9521"},{"name":"10743","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/10743/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-2331","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html","refsource":"CONFIRM","url":"http://www.macromedia.com/devnet/security/security_zone/mpsb04-01.html"},{"name":"coldfusion-mx-sandbox-bypass(14984)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/14984"},{"name":"9521","refsource":"BID","url":"http://www.securityfocus.com/bid/9521"},{"name":"10743","refsource":"SECUNIA","url":"http://secunia.com/advisories/10743/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-2331","datePublished":"2005-08-16T04:00:00.000Z","dateReserved":"2005-08-16T00:00:00.000Z","dateUpdated":"2024-08-08T01:22:13.663Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2004-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-470","n/a"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:macromedia:coldfusion:6.1:*:*:*:*:*:*:*","matchCriteriaId":"B2C65BE0-32FA-4D51-AA2B-E7D630470D19"},{"vulnerable":true,"criteria":"cpe:2.3:a:macromedia:coldfusion:6.1:*:j2ee_application_server:*:*:*:*:*","matchCriteriaId":"5E448558-A9F6-4506-AA6D-688C73CEC61E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"2331","Ordinal":"1","Title":"CVE-2004-2331","CVE":"CVE-2004-2331","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"2331","Ordinal":"1","NoteData":"ColdFusion MX 6.1 and 6.1 J2EE allows local users to bypass sandbox security restrictions and obtain sensitive information by using Java reflection methods to access trusted Java objects without using the CreateObject function or cfobject tag.","Type":"Description","Title":"CVE-2004-2331"},{"CveYear":"2004","CveId":"2331","Ordinal":"2","NoteData":"2005-08-16","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"2331","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}