XML External Entity Injection Vulnerability in Adobe ColdFusion
CVE-2017-11286

7.5HIGH

Summary

Adobe ColdFusion is impacted by an XML external entity (XXE) injection vulnerability that enables attackers to exploit the processing of specially crafted XML input. This vulnerability affects ColdFusion versions prior to Update 5 for ColdFusion 2016 and versions prior to Update 13 for ColdFusion 11. By executing a malicious XML document, an attacker may be able to access sensitive files or execute remote requests. Users are encouraged to apply the latest security updates to mitigate potential risks.

Affected Version(s)

Adobe ColdFusion Update 4 and earlier for ColdFusion 2016 release. Update 12 and earlier for ColdFusion 11. Adobe ColdFusion Update 4 and earlier versions for ColdFusion 2016 release. Update 12 and earlier versions for ColdFusion 11.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.