Security Bypass Vulnerability in ColdFusion by Adobe
CVE-2019-8072

7.5HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
27 September 2019

Summary

ColdFusion versions 2018 - update 4 and earlier, as well as 2016 - update 11 and earlier, are susceptible to a security bypass vulnerability. This vulnerability allows for the possibility of information disclosure in the context of the current user, potentially exposing sensitive data. It is essential for users and administrators to apply the latest updates from Adobe to mitigate this risk. For more detailed information, refer to Adobe's official security advisory.

Affected Version(s)

Cold Fusion ColdFusion 2018- update 4 and earlier

Cold Fusion ColdFusion 2016- update 11 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.