Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.
The product contains hard-coded credentials, such as a password or cryptographic key.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coldfusion | Adobe | 2018 (including) | 2018 (including) |
Coldfusion | Adobe | 2018-update1 (including) | 2018-update1 (including) |
Coldfusion | Adobe | 2018-update10 (including) | 2018-update10 (including) |
Coldfusion | Adobe | 2018-update11 (including) | 2018-update11 (including) |
Coldfusion | Adobe | 2018-update12 (including) | 2018-update12 (including) |
Coldfusion | Adobe | 2018-update13 (including) | 2018-update13 (including) |
Coldfusion | Adobe | 2018-update14 (including) | 2018-update14 (including) |
Coldfusion | Adobe | 2018-update2 (including) | 2018-update2 (including) |
Coldfusion | Adobe | 2018-update3 (including) | 2018-update3 (including) |
Coldfusion | Adobe | 2018-update4 (including) | 2018-update4 (including) |
Coldfusion | Adobe | 2018-update5 (including) | 2018-update5 (including) |
Coldfusion | Adobe | 2018-update6 (including) | 2018-update6 (including) |
Coldfusion | Adobe | 2018-update7 (including) | 2018-update7 (including) |
Coldfusion | Adobe | 2018-update8 (including) | 2018-update8 (including) |
Coldfusion | Adobe | 2018-update9 (including) | 2018-update9 (including) |
Coldfusion | Adobe | 2021 (including) | 2021 (including) |
Coldfusion | Adobe | 2021-update1 (including) | 2021-update1 (including) |
Coldfusion | Adobe | 2021-update2 (including) | 2021-update2 (including) |
Coldfusion | Adobe | 2021-update3 (including) | 2021-update3 (including) |
Coldfusion | Adobe | 2021-update4 (including) | 2021-update4 (including) |
There are two main variations: