Security Bypass Vulnerability in ColdFusion by Adobe
CVE-2019-8072
7.5HIGH
Summary
ColdFusion versions 2018 - update 4 and earlier, as well as 2016 - update 11 and earlier, are susceptible to a security bypass vulnerability. This vulnerability allows for the possibility of information disclosure in the context of the current user, potentially exposing sensitive data. It is essential for users and administrators to apply the latest updates from Adobe to mitigate this risk. For more detailed information, refer to Adobe's official security advisory.
Affected Version(s)
Cold Fusion ColdFusion 2018- update 4 and earlier
Cold Fusion ColdFusion 2016- update 11 and earlier
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved