Insecure Library Loading Vulnerability in Adobe ColdFusion Products
CVE-2018-4938

7.8HIGH

Summary

Adobe ColdFusion products, specifically Update 5 and earlier versions, as well as ColdFusion 11 Update 13 and earlier versions, are susceptible to an Insecure Library Loading vulnerability. This flaw allows attackers to exploit the system, potentially leading to local privilege escalation, enabling unauthorized access and control over affected systems. Organizations using these versions should implement necessary updates to mitigate risks associated with this vulnerability.

Affected Version(s)

Adobe ColdFusion ColdFusion Update 5 and earlier , ColdFusion 11 Update 13 and earlier Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.