Skip to main content

Adobe ColdFusion Multiple Vulnerabilities

Last Update Date: 26 Apr 2017 10:12 Release Date: 26 Apr 2017 2954 Views

RISK: Medium Risk

TYPE: Web services - Web Servers

TYPE: Web Servers

A XSS (cross-site scripting) vulnerability has been identified in Adobe Fusion.

A java deserialization vulnerability has been identified in Adobe Fusion.


Impact

  • Cross-Site Scripting
  • Data Manipulation

System / Technologies affected

  • ColdFusion (2016 release) Update 3 and earlier versions
  • ColdFusion 11 Update 11 and earlier versions  
  • ColdFusion 10 Update 22 and earlier versions  

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to ColdFusion (2016 release) Update 4
  • Update to ColdFusion 11 Update 12
  • Update to ColdFusion 10 Update 23

Vulnerability Identifier


Source


Related Link