VYPR
Unrated severityNVD Advisory· Published Jun 12, 2019· Updated Aug 4, 2024

CVE-2019-7840

CVE-2019-7840

Description

ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.

Affected products

2
  • Adobe Inc./Coldfusionllm-fuzzy2 versions
    ≤Update 18 for ColdFusion 2018, ≤Update 10 for ColdFusion 2016, ≤Update 3 for ColdFusion 11+ 1 more
    • (no CPE)range: ≤Update 18 for ColdFusion 2018, ≤Update 10 for ColdFusion 2016, ≤Update 3 for ColdFusion 11
    • (no CPE)range: Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier versions

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.