Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
2016-05-11T01:59:44.810
2025-04-12T10:46:40.837
Deferred
CVSSv3.1: 5.9 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 10.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |