Description
ColdFusion RDS Service is enabled and publicly available to any IP address. The service is intended for development use only and must be protected with a strong password.
Remediation
Disable RDS Service in the ColdFusion Administrator.
References
Related Vulnerabilities
PHP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-7128)
Node.js Inspector Unauthorized Access Vulnerability
Oracle E-Business Suite Information Disclosure
Weak Nonce Detected in Content Security Policy (CSP) Declaration
Squid Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-18679)