← Back

CVE-2019-7838

nvd nist
Published: Jun 12, 2019Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a file extension blacklist bypass vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected (34)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
34 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Version 11.0
Version 11.0 update10
Version 11.0 update11
Version 11.0 update12
Version 11.0 update13
Version 11.0 update14
Version 11.0 update15
Version 11.0 update16
Version 11.0 update17
Version 11.0 update18
Version 11.0 update1
Version 11.0 update2
Version 11.0 update3
Version 11.0 update4
Version 11.0 update5
Version 11.0 update6
Version 11.0 update7
Version 11.0 update8
Version 11.0 update9
Version 2016
Version 2016 update10
Version 2016 update1
Version 2016 update2
Version 2016 update3
Version 2016 update4
Version 2016 update5
Version 2016 update6
Version 2016 update7
Version 2016 update8
Version 2016 update9
Version 2018
Version 2018 update1
Version 2018 update2
Version 2018 update3

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.