← Back

CVE-2017-3066

nvd nist
Published: Apr 27, 2017Modified: Apr 22, 2026CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

Affected (39)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 10.0
Version 10.0 update10
Version 10.0 update11
Version 10.0 update12
Version 10.0 update13
Version 10.0 update14
Version 10.0 update15
Version 10.0 update16
Version 10.0 update17
Version 10.0 update18
Version 10.0 update19
Version 10.0 update1
Version 10.0 update20
Version 10.0 update21
Version 10.0 update22
Version 10.0 update2
Version 10.0 update3
Version 10.0 update4
Version 10.0 update5
Version 10.0 update6
Version 10.0 update7
Version 10.0 update8
Version 10.0 update9
Version 11.0
Version 11.0 update10
Version 11.0 update11
Version 11.0 update1
Version 11.0 update2
Version 11.0 update3
Version 11.0 update4
Version 11.0 update5
Version 11.0 update6
Version 11.0 update7
Version 11.0 update8
Version 11.0 update9
Version 2016
Version 2016 update1
Version 2016 update2
Version 2016 update3

References (9)

Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
Broken LinkThird Party AdvisoryVDB Entry
Source: psirt@adobe.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.