Cross-scripting flaws patched in Adobe app software
Adobe said that this time criminals haven’t had the time to take advantage of the vulnerabilities.

Adobe has released another update to secure vulnerabilities in its software, as its season of security woe continues.
Critical vulnerabilities were found its application development software ColdFusion and its J2EE application server JRun 4.0.
According to its latest security bulletin, the cross-scripting vulnerabilities could have led to the compromise of user accounts on the affected system.
In a blog post, Adobe claimed that it was not aware of any exploits in the wild for the flaws found in the release.
This is just the latest in a series of security warnings and patches over Adobe products in the past few months, which has forced the company to implement a patching scheme for some of its products.
At the beginning of the month Adobe had to release an out-of-cycle patch for Flash Player, AIR, Reader and Acrobat software.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Warning issued over “incomplete” fix for Adobe ColdFusion vulnerability
News An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
By Ross Kelly
-
Adobe forced to patch its own failed security update
News Company issues new fix for e-commerce vulnerability after researchers bypass the original update
By Danny Bradbury
-
Ask more from your CMS
Whitepaper How to get the most value in the shortest timespan
By ITPro
-
Adobe battles fake photos with editing tags
News Photoshop will include new tagging tools later this year to help fight against misinformation and deep fakes
By Nicole Kobie
-
What is cross-site scripting (XSS)?
In-depth How XSS exploits work and how to defend against them
By Dale Walker
-
Adobe Photoshop Elements 2019 review: Trapped in the photo-editing middle ground
Reviews A once peerless beginner’s photo-editing package that’s past its prime
By Barry Collins
-
Hackers infiltrated analytics platform used by 2m sites to syphon Bitcoin from gate.io
News “Supply-chain attack” saw more than 680,000 sites actively infected but the code only specified an address used by gate.io
By Keumars Afifi-Sabet
-
Vulnerabilities in web applications at the heart of 73% of breaches, Kaspersky finds
News Pen test analysis finds 43% of companies have low or extremely low levels of security
By Keumars Afifi-Sabet