spacer

Security hotfix available for ColdFusion

7

Posted in ColdFusion | Posted on 03-13-2012 | 465 views

Title says it all - we released a new hotfix for ColdFusion today: www.adobe.com/support/security/bulletins/apsb12-06.html

spacer

Comments

[Add Comment] [Subscribe to Comments]

Rick said on 03-13-2012 at 2:36 PM #
spacer
If only there were an easy way to ensure that all current updates (security and otherwise) are installed on a CF server......or is there? (Got any secrets you want to share? I only have under a dozen CF servers of various versions....so could use the help.)
Raymond Camden said on 03-13-2012 at 3:09 PM #
spacer
For security, you should make use of Foundeo's HackMyCF service. It sounds scary, but it's an incredible service that will scan your machines and report issues to you. It's free, with a paid version. I cannot recommend it enough.

As for everything else, unfortunately there isn't a real nice way to do this. ColdFusion 10 makes it easier since you can go to your CF Admin and check there though.
Michael Williams said on 03-13-2012 at 9:15 PM #
spacer
Wow. 14 steps to manually apply a security update. This is sad. I have a lot of servers. Adobe should do better than this.
Raymond Camden said on 03-13-2012 at 9:22 PM #
spacer
As I said above, ColdFusion 10 makes it easier. You can install hotfixes via the admin.
Michael Williams said on 03-13-2012 at 10:12 PM #
spacer
In a multi-server install would it be safe to patch the 1st instance: cfusion then build and ear from that instance and deploy new servers based on it using the Instance Manager? I suppose a .car could also work but I'm having trouble getting a .car created and deployed on my test server.
Raymond Camden said on 03-13-2012 at 10:15 PM #
spacer
Hate to say it - but no idea. I never use multiserver.
Michael Williams said on 03-13-2012 at 10:22 PM #
spacer
I got the Packaging & Deployment > J2EE Archives to make an ear of my /cfusion patched instance and then deployed it as a new instance /cfusion4 with all the settings and files from the /cfusion instance. It seems to be working. No errors thrown. This might be a good way to patch this monster on CF8 Enterprise if all your server instances share the same or near the same settings. Trying to find the support forums for CF on the adobe site to see if anyone else has tried this approach. I dont' think I've needed the support forums since the Macromedia days...

[Add Comment] [Subscribe to Comments]

spacer
gipoco.com is neither affiliated with the authors of this page nor responsible for its contents. This is a safe-cache copy of the original web site.