Skip to main content
January 14, 2013
Question

ColdFusion security problems

  • January 14, 2013
  • 2 replies
  • 676 views

This page says Adobe only supports ColdFusion 9 and 10, http://www.adobe.com/support/programs/policies/supported.html .

This page mentions some security problems for ColdFusion 9 and 10, http://www.adobe.com/support/security/advisories/apsa13-01.html .

We use version 8. Do you know if Adobe would report the security problems for an unsupported version - could version 8 have the vulnerabilities mentioned in the second link above ?

    This topic has been closed for replies.

    2 replies

    Inspiring
    January 14, 2013

    I'm not sure how it affects CF8, but you could still follow the mitigation recommendations without needing a patch. 

    You could also follow some of the lockdown guides and see how they apply to CF8. 

    Bill

    Legend
    January 14, 2013

    CF8 is EOL as of 31 July 2012

    http://helpx.adobe.com/coldfusion/kb/coldfusion-security-hotfix-apsb12-21.html

    says:

    This is last security fix for ColdFusion 8 and ColdFusion 8.0.1.

    HTH, Carl.