Skip to main content

Adobe ColdFusion Remote Code Execution Vulnerability

Last Update Date: 4 Mar 2019 10:43 Release Date: 4 Mar 2019 4645 Views

RISK: High Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

A vulnerability was identified in Adobe ColdFusion, a remote attacker can exploit this vulnerability to trigger remote code execution on the targeted system.

 

Notes: The vulnerability is being exploited in the wild.


Impact

  • Remote Code Execution

System / Technologies affected

  • ColdFusion 2018 Update 2 and earlier versions
  • ColdFusion 2016 Update 9 and earlier versions
  • ColdFusion 11 Update 17 and earlier versions

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 

Upgrade to latest version version:

  • ColdFusion 2018 Update 3
  • ColdFusion 2016 Update 10
  • ColdFusion 11 Update 18

Vulnerability Identifier


Source


Related Link