← Back

CVE-2021-40699

nvd nist
Published: Sep 7, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Exploitability: 3.1 / Impact: 3.7
Source: NVD

Description

ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.

Affected (13)

Products: Adobe: Coldfusion
1 product
Coldfusion
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Adobe
Before 2018
Version 2018
Version 2018 update10
Version 2018 update1
Version 2018 update2
Version 2018 update3
Version 2018 update4
Version 2018 update5
Version 2018 update6
Version 2018 update7
Version 2018 update8
Version 2018 update9
Version 2021

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.