ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 11.0 (including) | 11.0 (including) |
Coldfusion | Adobe | 11.0-update1 (including) | 11.0-update1 (including) |
Coldfusion | Adobe | 11.0-update10 (including) | 11.0-update10 (including) |
Coldfusion | Adobe | 11.0-update11 (including) | 11.0-update11 (including) |
Coldfusion | Adobe | 11.0-update12 (including) | 11.0-update12 (including) |
Coldfusion | Adobe | 11.0-update13 (including) | 11.0-update13 (including) |
Coldfusion | Adobe | 11.0-update14 (including) | 11.0-update14 (including) |
Coldfusion | Adobe | 11.0-update15 (including) | 11.0-update15 (including) |
Coldfusion | Adobe | 11.0-update16 (including) | 11.0-update16 (including) |
Coldfusion | Adobe | 11.0-update17 (including) | 11.0-update17 (including) |
Coldfusion | Adobe | 11.0-update18 (including) | 11.0-update18 (including) |
Coldfusion | Adobe | 11.0-update2 (including) | 11.0-update2 (including) |
Coldfusion | Adobe | 11.0-update3 (including) | 11.0-update3 (including) |
Coldfusion | Adobe | 11.0-update4 (including) | 11.0-update4 (including) |
Coldfusion | Adobe | 11.0-update5 (including) | 11.0-update5 (including) |
Coldfusion | Adobe | 11.0-update6 (including) | 11.0-update6 (including) |
Coldfusion | Adobe | 11.0-update7 (including) | 11.0-update7 (including) |
Coldfusion | Adobe | 11.0-update8 (including) | 11.0-update8 (including) |
Coldfusion | Adobe | 11.0-update9 (including) | 11.0-update9 (including) |
Coldfusion | Adobe | 2016 (including) | 2016 (including) |
Coldfusion | Adobe | 2016-update1 (including) | 2016-update1 (including) |
Coldfusion | Adobe | 2016-update10 (including) | 2016-update10 (including) |
Coldfusion | Adobe | 2016-update2 (including) | 2016-update2 (including) |
Coldfusion | Adobe | 2016-update3 (including) | 2016-update3 (including) |
Coldfusion | Adobe | 2016-update4 (including) | 2016-update4 (including) |
Coldfusion | Adobe | 2016-update5 (including) | 2016-update5 (including) |
Coldfusion | Adobe | 2016-update6 (including) | 2016-update6 (including) |
Coldfusion | Adobe | 2016-update7 (including) | 2016-update7 (including) |
Coldfusion | Adobe | 2016-update8 (including) | 2016-update8 (including) |
Coldfusion | Adobe | 2016-update9 (including) | 2016-update9 (including) |
Coldfusion | Adobe | 2018 (including) | 2018 (including) |
Coldfusion | Adobe | 2018-update1 (including) | 2018-update1 (including) |
Coldfusion | Adobe | 2018-update2 (including) | 2018-update2 (including) |
Coldfusion | Adobe | 2018-update3 (including) | 2018-update3 (including) |