Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
2018-09-25T13:29:01.363
2025-05-06T15:15:53.677
Modified
CVSSv3.1: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 11.0 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2016 | Yes |
Application | adobe | coldfusion | 2018 | Yes |