Description
ColdFusion RDS Service is enabled and publicly available to any IP address. The service is intended for development use only and must be protected with a strong password.
Remediation
Disable RDS Service in the ColdFusion Administrator.
References
Related Vulnerabilities
WordPress Plugin WP Intercom-Slack for WordPress Information Disclosure (1.2.1)
WordPress Plugin iThemes Security (formerly Better WP Security) Information Disclosure (5.1.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-2243)