VYPR
Critical severity9.8NVD Advisory· Published Dec 19, 2019· Updated Jun 17, 2026

CVE-2019-8256

CVE-2019-8256

Description

ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.

Affected products

9
  • Update 6 and earlier versions+ 8 more
    • (no CPE)range: Update 6 and earlier versions
    • (no CPE)range: <=Update 6
    • cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.