FNAL Critical Vulnerability - Exposing Adobe ColdFusion Servers to the Internet

Effective Date: 10/5/2012
Product: Adobe ColdFusion (All Versions)
Platform: All Platforms

Due to various successful exploits against Adobe ColdFusion servers, FNAL prohibits onsite ColdFusion servers from being accessed from, or available to, the Internet. If you run an Adobe ColdFusion server, you must:
- Ensure it is CONSISTENTLY at the latest release and patch levels
- Permit access from ONLY the FNAL addresses, or SPECIFIC FNAL addresses
- PROHIBIT access to the ColdFusion instances from the Internet

For assistance contact servicedesk@fnal.gov.
Information compiled and maintained by Computer Security Team ; last modified on Oct 5, 2012.
(Address comments about page to the Computer Security Team.)