<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title>ColdFusion 9 Security Patches</title>
    <link>http://www.merlinmanager.com/</link>
    <description>ColdFusion 9 Security Patches</description>
    <language>en-us</language>

	
    <item>
      <title>APSB13-27 Unauthorized Remote Read</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb13-27.html</link>
      <description><![CDATA[Adobe has released a security hotfix for ColdFusion versions 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and Linux.  This hotfix addresses a reflected cross site scripting vulnerability (CVE-2013-5326) that could be exploited by a remote, authenticated user on ColdFusion 10 and earlier when the CFIDE directory is exposed. 

This hotfix also addresses a vulnerability (CVE-2013-5328) in ColdFusion 10 that could permit unauthorized remote read access.]]></description>
	  <category>Manual</category>
	  <category>9.0.2</category>
      <pubDate>Wed, 13 Nov 2013 20:14:14 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb13-27.html</guid>
    </item>
	
    <item>
      <title>APSB13-19 Security Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb13-19.html</link>
      <description><![CDATA[Adobe has released a security hotfix for ColdFusion versions 9.0, 9.0.1 and 9.0.2 on JRun.  This hotfix addresses a vulnerability (CVE-2013-3349) that could be exploited to cause a denial of service condition on a system running ColdFusion 9.0, 9.0.1 and 9.0.2 on JRun.]]></description>
	  <category>Manual</category>
	  <category>9.0.2</category>
      <pubDate>Tue, 16 Jul 2013 21:23:17 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb13-19.html</guid>
    </item>
	
    <item>
      <title>APSB13-10 Security Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb13-10.html</link>
      <description><![CDATA[Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 10, 9.0.1 before Update 9, 9.0.2 before Update 4, and 10 before Update 9 allows attackers to impersonate users via unknown vectors]]></description>
	  <category>Manual</category>
	  <category>9.0.2</category>
      <pubDate>Wed, 10 Apr 2013 19:21:08 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb13-10.html</guid>
    </item>
	
    <item>
      <title>APSB13-03 RDS Security Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb13-03.html</link>
      <description><![CDATA[Adobe has released a security hotfix for ColdFusion 10, 9.0.2, 9.0.1 and 9.0 for Windows, Macintosh and UNIX.  This hotfix addresses vulnerabilities that could permit an unauthorized user to remotely circumvent authentication controls, potentially allowing the attacker to take control of the affected server.]]></description>
	  <category>Manual</category>
	  <category>9.0.2</category>
      <pubDate>Wed, 16 Jan 2013 12:52:49 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb13-03.html</guid>
    </item>
	
    <item>
      <title>APSB12-21 DOS Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb12-21.html</link>
      <description><![CDATA[Adobe has released a security hotfix for ColdFusion 10 and earlier versions for Windows, Macintosh and UNIX. This update resolves a vulnerability which could result in a Denial of Service condition]]></description>
	  <category>Manual</category>
	  <category>9.0.2</category>
      <pubDate>Wed, 12 Sep 2012 11:54:56 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb12-21.html</guid>
    </item>
	
    <item>
      <title>APSB12-15 HTTP response splitting vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb12-15.html</link>
      <description><![CDATA[Adobe released a security hotfix for ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. This update resolves an HTTP response splitting vulnerability in the ColdFusion Component Browser.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Fri, 15 Jun 2012 04:56:49 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb12-15.html</guid>
    </item>
	
    <item>
      <title>APSB11-29 Cross-Site Scripting Vulnerabilities</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb11-29.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site scripting attack. Adobe has provided a solution to address the reported vulnerabilities. 

This update resolves a cross-site scripting vulnerability in cfform tag (CVE-2011-2463).

This update resolves a cross-site scripting vulnerability in RDS (CVE-2011-4368).]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 14 Dec 2011 01:20:28 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb11-29.html</guid>
    </item>
	
    <item>
      <title>APSB11-15 Security update available for LiveCycle Data Services and BlazeDS</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb11-15.html</link>
      <description><![CDATA[ColdFusion 9 uses BlazeDS 4 for data services. This patch applies to BlazeDS 4. Two important security vulnerabilities have been identified in LiveCycle Data Services and BlazeDS. These vulnerabilities affect LiveCycle Data Services 3.1, 2.6.1, 2.5.1 and earlier versions for Windows, Macintosh and UNIX, and LiveCycle 9.0.0.2, 8.2.1.3, 8.0.1.3 and earlier versions for Windows, Linux and UNIX. These vulnerabilities also affect BlazeDS 4.0.0 and earlier versions. Adobe recommends users update their product installations using the instructions provided in the "Solution" section below.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Thu, 21 Jul 2011 04:37:25 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb11-15.html</guid>
    </item>
	
    <item>
      <title>APSB11-14 DOS and CSRF Security Patch</title>
      <link>http://kb2.adobe.com/cps/907/cpsid_90784.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to a cross-site request forgery (CSRF) or a remote denial-of-service (DoS).]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Thu, 21 Jul 2011 02:33:49 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/907/cpsid_90784.html</guid>
    </item>
	
    <item>
      <title>APSB11-04 XSS, Session Fixation, CRLF injection Vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/890/cpsid_89094.html</link>
      <description><![CDATA[Important vulnerabilities have been identified in ColdFusion 9.0.1 and earlier versions for Windows, Macintosh and UNIX. These vulnerabilities could lead to cross-site scripting, Session Fixation, CRLF injection and information disclosure. Adobe recommends users update their product installation using the instructions provided below.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 09 Feb 2011 04:34:42 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/890/cpsid_89094.html</guid>
    </item>
	
    <item>
      <title>APSB10-18 Directory Traversal Vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb10-18.html</link>
      <description><![CDATA[An important vulnerability has been identified in ColdFusion 8.0, 8.0.1, 9.0, 9.0.1 for Windows, Macintosh and UNIX. This directory traversal vulnerability could lead to information disclosure (CVE-2010-2861). Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installation using the instructions provided above.]]></description>
	  <category>Manual</category>
	  <category>9.0.1</category>
      <pubDate>Wed, 11 Aug 2010 01:04:16 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb10-18.html</guid>
    </item>
	
    <item>
      <title>APSB10-11 ColdFusion cross-site scripting vulnerabilities</title>
      <link>http://kb2.adobe.com/cps/841/cpsid_84102.html</link>
      <description><![CDATA[Hotfix for cross-script scripting vulnerabilities in the CF Admin, componentutils and wizards login pages all in the CFIDE directory. This is a manual patch.\r\n\r\nA bug was found in this hotfix that affected CF8 64 bit installations and resolved by Adobe on May 13, 2010.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Thu, 13 May 2010 11:05:03 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/841/cpsid_84102.html</guid>
    </item>
	
    <item>
      <title>APSB10-05 Security update for Flash Remoting</title>
      <link>http://kb2.adobe.com/cps/822/cpsid_82241.html</link>
      <description><![CDATA[ColdFusion 9.0, 8.0.x and 7.0.2 are affected with the issue mentioned in the security bulletin APSB10-05 for BlazeDS. This technote provides fixes for the security issue along with the installation instructions.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Fri, 19 Feb 2010 00:00:40 GMT</pubDate>
      <guid>http://kb2.adobe.com/cps/822/cpsid_82241.html</guid>
    </item>
	
    <item>
      <title>APSB10-04 Solr collection vulnerability</title>
      <link>http://www.adobe.com/support/security/bulletins/apsb10-04.html</link>
      <description><![CDATA[An important vulnerability (CVE-2010-0185) has been identified in ColdFusion 9.0, which could allow access to collections created by the Solr Service to be accessed from any external machine using a specific URL. Adobe has provided a solution to the reported vulnerability. It is recommended that users update their product installations using the instructions provided below.]]></description>
	  <category>Manual</category>
	  <category>9.0</category>
      <pubDate>Sat, 30 Jan 2010 00:00:21 GMT</pubDate>
      <guid>http://www.adobe.com/support/security/bulletins/apsb10-04.html</guid>
    </item>
	

  </channel>
</rss>
