<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss version="2.0">
  <channel>
    <title>ColdFusion 9 Security Patches</title>
    <link>http://www.merlinmanager.com/</link>
    <description>ColdFusion 9 Security Patches</description>
    <language>en-us</language>

	
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Coldfusion9SecurityPatches" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="coldfusion9securitypatches" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
      <title>APSB11-29 Cross-Site Scripting Vulnerabilities</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb11-29.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site scripting attack. Adobe has provided a solution to address the reported vulnerabilities. 

This update resolves a cross-site scripting vulnerability in cfform tag (CVE-2011-2463).

This update resolves a cross-site scripting vulnerability in RDS (CVE-2011-4368).]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 14 Dec 2011 01:20:28 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb11-29.html</guid>
    </item>
	
    <item>
      <title>APSB11-15 Security update available for LiveCycle Data Services and BlazeDS</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb11-15.html</link>
      <description><![CDATA[ColdFusion 9 uses BlazeDS 4 for data services. This patch applies to BlazeDS 4. Two important security vulnerabilities have been identified in LiveCycle Data Services and BlazeDS. These vulnerabilities affect LiveCycle Data Services 3.1, 2.6.1, 2.5.1 and earlier versions for Windows, Macintosh and UNIX, and LiveCycle 9.0.0.2, 8.2.1.3, 8.0.1.3 and earlier versions for Windows, Linux and UNIX. These vulnerabilities also affect BlazeDS 4.0.0 and earlier versions. Adobe recommends users update their product installations using the instructions provided in the "Solution" section below.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Thu, 21 Jul 2011 04:37:25 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb11-15.html</guid>
    </item>
	
    <item>
      <title>APSB11-14 DOS and CSRF Security Patch</title>
      <link>http://kb2.adobe.com/cps/907/cpsid_90784.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site request forgery (CSRF) or a remote denial-of-service (DoS).]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Thu, 21 Jul 2011 02:33:49 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/907/cpsid_90784.html</guid>
    </item>
	
    <item>
      <title>APSB11-04 XSS, Session Fixation, CRLF injection Vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/890/cpsid_89094.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to cross-site scripting, Session Fixation, CRLF injection and information disclosure. Adobe recommends users update their product installation using the instructions provided below.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 09 Feb 2011 04:34:42 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/890/cpsid_89094.html</guid>
    </item>
	
    <item>
      <title>APSB10-18 Directory Traversal Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb10-18.html</link>
      <description><![CDATA[An important vulnerability has been identified in ColdFusion 8.0, 8.0.1, 9.0, 9.0.1 for Windows, Macintosh and UNIX. This directory traversal vulnerability could lead to information disclosure (CVE-2010-2861). Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installation using the instructions provided above.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 11 Aug 2010 01:04:16 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb10-18.html</guid>
    </item>
	
    <item>
      <title>APSB10-11 ColdFusion cross-site scripting vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/841/cpsid_84102.html</link>
      <description><![CDATA[Hotfix for cross-script scripting vulnerabilities in the CF Admin, componentutils and wizards login pages all in the CFIDE directory. This is a manual patch.\r\n\r\nA bug was found in this hotfix that affected CF8 64 bit installations and resolved by Adobe on May 13, 2010.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Thu, 13 May 2010 11:05:03 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/841/cpsid_84102.html</guid>
    </item>
	
    <item>
      <title>APSB10-05 Security update for Flash Remoting</title>
      <link>http://kb2.adobe.com/cps/822/cpsid_82241.html</link>
      <description><![CDATA[ColdFusion 9.0, 8.0.x and 7.0.2 are affected with the issue mentioned in the security bulletin APSB10-05 for BlazeDS. This technote provides fixes for the security issue along with the installation instructions.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Fri, 19 Feb 2010 00:00:40 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/822/cpsid_82241.html</guid>
    </item>
	
    <item>
      <title>APSB10-04 Solr collection vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb10-04.html</link>
      <description><![CDATA[An important vulnerability (CVE-2010-0185) has been identified in ColdFusion 9.0, which could allow access to collections created by the Solr Service to be accessed from any external machine using a specific URL. Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installations using the instructions provided below.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Sat, 30 Jan 2010 00:00:21 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb10-04.html</guid>
    </item>
	

  </channel>
</rss>

