Unsafe XML External Entity Processing in Adobe ColdFusion
CVE-2018-4942
7.5HIGH
Key Information:
- Vendor
Adobe
- Vendor
- CVE Published:
- 19 May 2018
What is CVE-2018-4942?
Adobe ColdFusion versions up to Update 5 and ColdFusion 11 up to Update 13 are prone to an unsafe XML External Entity (XXE) processing vulnerability. This flaw allows attackers to exploit XML parsers that improperly handle user-controlled input. Successful exploitation may result in unauthorized information disclosure, thereby compromising the confidentiality of sensitive data. Organizations using these versions of ColdFusion should apply necessary updates and follow best practices for securing XML processing.
Affected Version(s)
Adobe ColdFusion ColdFusion Update 5 and earlier , ColdFusion 11 Update 13 and earlier Adobe ColdFusion ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions