← Back

CVE-2018-4939

nvd nist
Published: May 19, 2018Modified: Oct 23, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected (20)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
20 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 11.0
Version 11.0 update10
Version 11.0 update11
Version 11.0 update12
Version 11.0 update13
Version 11.0 update1
Version 11.0 update2
Version 11.0 update3
Version 11.0 update4
Version 11.0 update5
Version 11.0 update6
Version 11.0 update7
Version 11.0 update8
Version 11.0 update9
Version 2016
Version 2016 update1
Version 2016 update2
Version 2016 update3
Version 2016 update4
Version 2016 update5

References (5)

Source: psirt@adobe.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.