Skip to main content
eccentricDBA
Inspiring
May 13, 2010
Question

Does ColdFusion : Security Bulletin APSB10-11 apply to MX 7.0.2

  • May 13, 2010
  • 3 replies
  • 1343 views

I contacted adobe phone support and was directed to post my question to the forum because adobe doesn't provide phone support for server products.

So, Does ColdFusion : Security Bulletin APSB10-11 apply to MX 7.0.2?

In the Security Bulleting it reads like it does:

Summary

Important vulnerabilities have been identified in ColdFusion 8.0, 8.0.1, 9.0 and earlier versions for Windows, Macintosh and UNIX. The vulnerabilities could lead to cross-site scripting and information disclosure.

source: http://www.adobe.com/support/security/bulletins/apsb10-11.html

However, there are no solutions in the technote:

Issue


Note: This technote and the attachments have been updated on 05/13/2010. All ColdFusion users should review the technote again. An issue when this security fix was applied with Cumulative Hot Fix 4 for ColdFusion 8.0.1 has been identified and resolved. The issue was caused by a naming conflict.

ColdFusion 9.0, 8.0.1 and 8.0 are affected with the issue mentioned in the security bulletin APSB10-11. This technote provides fixes for the security issues along with the installation instructions.

source: http://kb2.adobe.com/cps/841/cpsid_84102.html

Additionally, does anyone know if Cold Fusion MX 7.0.2 is a supported product?

Thank you any help will be benifitial.

    This topic has been closed for replies.

    3 replies

    May 17, 2010

    So dnyone know if this issue affects version 7.02 or earlier? If so, I'm sure there are quite a few developers/admins who would like to hear what can be done, if anything to battle this issue.

    I  can't imagine Adobe would leave all earlier versions  out to the wolves?

    Participant
    May 17, 2010

    My understanding from Adobe sales and ASAP Software (now Dell) reps is that security related issues will be fixed by Adobe until the product enters the End of Life, which is 02-07-2012.  Of course salepeople are not the ones actually responsible for supporting the products, and I have never successfully contacted Adobe Tech support since the 3rd party call center Adobe outsourced to could not figure out how to write a quote for a support incident so I could pay for it via a PO!

    I am also waiting for an updated CFForms jar, since the digital certificate expires in 2 days and I have been contacting Adobe for over 6 months without a reply on that issue.  I hope they clarify MX 7.0.2 support quickly and issue the fixes ASAP, or at least update the bulletins.

    eccentricDBA
    Inspiring
    May 17, 2010

    Thank you all this information has been usefull.

    @Adam the document you reference is extremely helpful.  I would had thought the Security Patches are still address during "Extended Support".  However, this may be why it's getting extremely more dificult to determine which Security Bulletins affect 7.0.2.

    @Ian. Yes my concern is that MX 7.0.2 is effected by APSB 10-11 with no patch available.  I know the last few patches I had to dive into the 9 and 8 bulittens to determine that they effect 7.0.2.  According to Adobe - Secuirty bullentins ( http://www.adobe.com/support/security/#coldfusion ) the last patch for 7.0.2 is APSB08-21 Update available for potential ColdFusion 8 privilege escalation issue however I know that APSB09-12 Security Update: Hotfixes available for ColdFusion and JRun also applied to 7.0.2 but was only listed in the Cold Fusion 8 section.

    Inspiring
    May 13, 2010

    I contacted adobe phone support and was directed to post my question to the forum because adobe doesn't provide phone support for server products.

    I have had phone support from them, and they were quite helpful.  Do you mean they don't do free phone support?  No, they don't.

    I cannot believe they suggested you raise an issue on the forum.  That's just sh!t.  There's no other way of describing that.

    Additionally, does anyone know if Cold Fusion MX 7.0.2 is a supported product?

    http://www.adobe.com/support/products/enterprise/eol/eol_matrix.html#63

    Only for "Extended support", whatever that is.

    [searches]

    Hmmm... http://www.adobe.com/support/programs/policies/terms_customer.html:


    Extended Support. If version of software held by Customer at time of renewal has been end-of-lifed during the next renewal term, Customer may renew to Extended Support, provided that Extended Support is available for such software version.  Information about Software that has been or soon will be end-of-lifed and Extended Support availability dates by product version are published at www.adobe.com/support. If Customer elects to purchase Extended Support, the Annual Support Fee shall be twenty-five (25%) percent of the license fee paid for the Software (if such fee cannot be established, the percentage would be based on the then-current list price of the license fee for the Software), however in no event shall the amount be less than the last renewal prior to renewing under Extended Support.

    If extended support is renewed, the renewal fee would be the Annual Support Fee paid for the prior year increased by the applicable Consumer Price Index (CPI)*, for the 12-month period preceding the renewal date. Should Customer upgrade to the next major version of the Software (e.g., upgrade from 4.0 to 5.0), the Annual Support Fee for the upgraded version shall be the lesser of twenty percent (20%) of the then current list price of the license fee for such upgraded version, or the Annual Support Fee for the last renewal prior to renewing under Extended Support increased by the applicable Consumer Price Index (CPI)*, for the 12-month period preceding the renewal date.

    So there you go.  It's something you'd have to be paying for anyhow, and my reading of that is that it's too late to get it now anyhow.

    I think this will also mean that you're definitely out of luck in regards to any sort of patching going on for CFMX7.

    --

    Adam

    May 17, 2010

    I dug around a little as well and couldn't find any mention of whether 7.02 is affected, or any earlier versions for that matter. Has anyone heard differently?

    ilssac
    Inspiring
    May 17, 2010

    One of the notices that I read had language such as this:

    Affected software versions

    ColdFusion 8.0, 8.0.1, 9.0 and earlier versions for Windows, Macintosh and UNIX

    How you inturpt "and earlier versions" is probably the crux of your question.  But that was the language used by Adobe.