Coldfusion and the Java CVE-2012-1723 vulnerability.
i have few questions coldfusion, me 9.0.1, regarding java. updated jvm coldfusion in past due vulnerability version sanctified adobe use, version 1.6.0_24. vulnerability: cve-2010-4476
so first particular vulnerability, cve-2012-1723, applicable coldfusion server? second, current version of java sanctified adobe? last, consequences of using non-sanctified version of java coldfusion?
adobe has not "certified" coldfusion 9 on newer version of jvm version 1.6.0_24. unofficial word on street adobe support still work if have newer jvm, though might ask roll 1.6.0_24. adobe has certified new version of jvm outside of major release twice recollection, first time when day light savings time rules changed, , second dos vulnerability exists in versions prior 1.6_0_24. adobe supporting java 7 cf9 , 10 due java6 eol per blog entry: http://blogs.coldfusion.com/post.cfm/java-7-support-for-coldfusion vulnerability cve-2012-1723 allows bypass of java security sandboxs, might concerned on coldfusion server... if have sandbox security turned on.
More discussions in ColdFusion
adobe
Comments
Post a Comment