Macromedia JRun Unauthorized Session Access Vulnerability
BID:14271
Info
Macromedia JRun Unauthorized Session Access Vulnerability
| Bugtraq ID: | 14271 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2005 12:00AM |
| Updated: | Jul 15 2005 12:00AM |
| Credit: | Discovery is credited to Greg Ball. |
| Vulnerable: |
Macromedia JRun 4.0 SP1a Macromedia JRun 4.0 SP1 Macromedia JRun 4.0 build 61650 Macromedia JRun 4.0 Macromedia ColdFusion MX Enterprise with JRun 6.1 Macromedia ColdFusion MX Enterprise Multi-Server Edition 7.0 |
| Not Vulnerable: | |
Discussion
Macromedia JRun Unauthorized Session Access Vulnerability
Macromedia JRun is affected by a vulnerability that may allow a user's session to be shared with another user.
Under certain circumstances, two users may share the same session facilitating various attacks including a compromise of the user's account.
It should be noted that this issue cannot be triggered by an attacker and occurs rarely.
JRun 4.0, ColdFusion MX 7.0 Enterprise Multi-Server Edition, and ColdFusion MX 6.1 Enterprise with JRun are affected by this vulnerability.
Macromedia JRun is affected by a vulnerability that may allow a user's session to be shared with another user.
Under certain circumstances, two users may share the same session facilitating various attacks including a compromise of the user's account.
It should be noted that this issue cannot be triggered by an attacker and occurs rarely.
JRun 4.0, ColdFusion MX 7.0 Enterprise Multi-Server Edition, and ColdFusion MX 6.1 Enterprise with JRun are affected by this vulnerability.
Exploit / POC
Macromedia JRun Unauthorized Session Access Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Macromedia JRun Unauthorized Session Access Vulnerability
Solution:
Macromedia has released an advisory including a patch for JRun 4.0. Please see the referenced advisory for more information about obtaining the patch.
Solution:
Macromedia has released an advisory including a patch for JRun 4.0. Please see the referenced advisory for more information about obtaining the patch.
References
Macromedia JRun Unauthorized Session Access Vulnerability
References:
References:
- ColdFusion MX Home Page (Macromedia)
- JRun Homepage (Adobe)