Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.
2018-09-25T13:29:01.817
2025-05-06T15:15:54.020
Modified
CVSSv3.1: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 11.0 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2016 | Yes |
| Application | adobe | coldfusion | 2018 | Yes |