Critical severity9.8NVD Advisory· Published Dec 19, 2019· Updated Jun 17, 2026
CVE-2019-8256
CVE-2019-8256
Description
ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
Affected products
9Update 6 and earlier versions+ 8 more
- (no CPE)range: Update 6 and earlier versions
- (no CPE)range: <=Update 6
- cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/coldfusion/apsb19-58.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.