{"api_version":"1","generated_at":"2026-07-23T06:07:29+00:00","cve":"CVE-2010-0185","urls":{"html":"https://cve.report/CVE-2010-0185","api":"https://cve.report/api/cve/CVE-2010-0185.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-0185","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-0185"},"summary":{"title":"CVE-2010-0185","description":"The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.","state":"PUBLISHED","assigner":"adobe","published_at":"2010-02-03 18:30:00","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55997","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55997","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://kb2.adobe.com/cps/807/cpsid_80719.html","name":"http://kb2.adobe.com/cps/807/cpsid_80719.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ColdFusion 9: How to limit access to the Solr collections","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/0259","name":"http://www.vupen.com/english/advisories/2010/0259","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/38007","name":"http://www.securityfocus.com/bid/38007","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe ColdFusion Solr Service Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.adobe.com/support/security/bulletins/apsb10-04.html","name":"http://www.adobe.com/support/security/bulletins/apsb10-04.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe - Security Bulletins: APSB10-04 Solution available for potential ColdFusion information disclosure issue","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/62037","name":"http://osvdb.org/62037","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1023519","name":"http://www.securitytracker.com/id?1023519","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe ColdFusion Discloses Solr Service Collections to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38387","name":"http://secunia.com/advisories/38387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Adobe ColdFusion Solr Collections Information Disclosure - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-0185","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-0185","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"185","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"coldfusion","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T00:37:54.126Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"38007","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/38007"},{"name":"ADV-2010-0259","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/0259"},{"name":"1023519","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1023519"},{"name":"coldfusion-solr-information-disclosure(55997)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55997"},{"name":"38387","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38387"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://kb2.adobe.com/cps/807/cpsid_80719.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-04.html"},{"name":"62037","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/62037"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-01-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"078d4453-3bcd-4900-85e6-15281da43538","shortName":"adobe"},"references":[{"name":"38007","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/38007"},{"name":"ADV-2010-0259","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/0259"},{"name":"1023519","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1023519"},{"name":"coldfusion-solr-information-disclosure(55997)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55997"},{"name":"38387","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38387"},{"tags":["x_refsource_CONFIRM"],"url":"http://kb2.adobe.com/cps/807/cpsid_80719.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/security/bulletins/apsb10-04.html"},{"name":"62037","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/62037"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@adobe.com","ID":"CVE-2010-0185","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"38007","refsource":"BID","url":"http://www.securityfocus.com/bid/38007"},{"name":"ADV-2010-0259","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/0259"},{"name":"1023519","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1023519"},{"name":"coldfusion-solr-information-disclosure(55997)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/55997"},{"name":"38387","refsource":"SECUNIA","url":"http://secunia.com/advisories/38387"},{"name":"http://kb2.adobe.com/cps/807/cpsid_80719.html","refsource":"CONFIRM","url":"http://kb2.adobe.com/cps/807/cpsid_80719.html"},{"name":"http://www.adobe.com/support/security/bulletins/apsb10-04.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/security/bulletins/apsb10-04.html"},{"name":"62037","refsource":"OSVDB","url":"http://osvdb.org/62037"}]}}}},"cveMetadata":{"assignerOrgId":"078d4453-3bcd-4900-85e6-15281da43538","assignerShortName":"adobe","cveId":"CVE-2010-0185","datePublished":"2010-02-03T18:00:00.000Z","dateReserved":"2010-01-06T00:00:00.000Z","dateUpdated":"2024-08-07T00:37:54.126Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-02-03 18:30:00","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:coldfusion:9.0:*:*:*:*:*:*:*","matchCriteriaId":"113431FB-E4BE-4416-800C-6B13AD1C0E92"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"185","Ordinal":"1","Title":"CVE-2010-0185","CVE":"CVE-2010-0185","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"185","Ordinal":"1","NoteData":"The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.","Type":"Description","Title":"CVE-2010-0185"},{"CveYear":"2010","CveId":"185","Ordinal":"2","NoteData":"2010-02-03","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"185","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}