Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 10.0 (including) | 10.0 (including) |
Coldfusion | Adobe | 10.0-update1 (including) | 10.0-update1 (including) |
Coldfusion | Adobe | 10.0-update10 (including) | 10.0-update10 (including) |
Coldfusion | Adobe | 10.0-update11 (including) | 10.0-update11 (including) |
Coldfusion | Adobe | 10.0-update12 (including) | 10.0-update12 (including) |
Coldfusion | Adobe | 10.0-update13 (including) | 10.0-update13 (including) |
Coldfusion | Adobe | 10.0-update14 (including) | 10.0-update14 (including) |
Coldfusion | Adobe | 10.0-update15 (including) | 10.0-update15 (including) |
Coldfusion | Adobe | 10.0-update16 (including) | 10.0-update16 (including) |
Coldfusion | Adobe | 10.0-update17 (including) | 10.0-update17 (including) |
Coldfusion | Adobe | 10.0-update18 (including) | 10.0-update18 (including) |
Coldfusion | Adobe | 10.0-update2 (including) | 10.0-update2 (including) |
Coldfusion | Adobe | 10.0-update3 (including) | 10.0-update3 (including) |
Coldfusion | Adobe | 10.0-update4 (including) | 10.0-update4 (including) |
Coldfusion | Adobe | 10.0-update5 (including) | 10.0-update5 (including) |
Coldfusion | Adobe | 10.0-update6 (including) | 10.0-update6 (including) |
Coldfusion | Adobe | 10.0-update7 (including) | 10.0-update7 (including) |
Coldfusion | Adobe | 10.0-update8 (including) | 10.0-update8 (including) |
Coldfusion | Adobe | 10.0-update9 (including) | 10.0-update9 (including) |
Coldfusion | Adobe | 11.0 (including) | 11.0 (including) |
Coldfusion | Adobe | 11.0-update1 (including) | 11.0-update1 (including) |
Coldfusion | Adobe | 11.0-update2 (including) | 11.0-update2 (including) |
Coldfusion | Adobe | 11.0-update3 (including) | 11.0-update3 (including) |
Coldfusion | Adobe | 11.0-update4 (including) | 11.0-update4 (including) |
Coldfusion | Adobe | 11.0-update5 (including) | 11.0-update5 (including) |
Coldfusion | Adobe | 11.0-update6 (including) | 11.0-update6 (including) |
Coldfusion | Adobe | 11.0-update7 (including) | 11.0-update7 (including) |
Coldfusion | Adobe | 2016 (including) | 2016 (including) |