PT-2019-3371 · Adobe · Coldfusion

Publicado

2019-09-24

·

Atualizado

2020-09-04

·

CVE-2019-8073

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2018 update 4 and earlier ColdFusion versions 2016 update 11 and earlier
Description The issue is related to the possibility of injecting external commands through a vulnerable module of the ColdFusion platform. This could allow a remote attacker to execute arbitrary code in the context of the current user.
Recommendations For ColdFusion 2018 update 4 and earlier, update to a version later than update 4 to resolve the issue. For ColdFusion 2016 update 11 and earlier, update to a version later than update 11 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable component to minimize the risk of exploitation.

Correção

OS Command Injection

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03501
CVE-2019-8073

Produtos afetados

Coldfusion