ColdFusion 9.0.1, ColdFusion 9, ColdFusion 8.0.1, and ColdFusion 8 are affected with vulnerabilities mentioned in the security bulletins APSB11-14 and APSB11-15. This TechNote provides fixes for the security issues mentioned in both the bulletins along with the installation instructions.
Note – Updated on Spetember 16 2011
A new issue was found with the security hot fix released with this TechNote. Applying the security hot fix causes ColdFusion to throw session is invalid errors randomly if the J2EE sessions are enabled.
Adobe has updated the hot fix files to include the fixes for the above issue. There are also additional instructions to apply the fix for the above issue only.
- Customers who have already applied the security hot fix, go here to apply the individual fix for this issue. Apply this fix after applying the fix released on July 26.
- Customers, who have not applied the security hot fix, follow the instructions to apply the complete fix.
Note - Updated on July 20 2011
Following bugs were reported against this security bulletin hot fix
1. Verify Data sources functionality broken for all ColdFusion versions.
2. Build number is missing for CF801
3. Thunbs.db file is present in some hot-fix zips.
Adobe has updated the hot fix files to include the fixes for the above issues and have also added additional instructions to apply the fix for the above issues only.
- Customers who have already applied the security hot fix, go here to apply the additional fix.
- Customers who have not applied the security hot fix, follow the instructions below. Hot fix files include the fixes for the above issues.

