PT-2018-16643 · Adobe · Coldfusion

Published

2018-05-19

·

Updated

2025-05-06

·

CVE-2018-4942

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions Update 5 and earlier Adobe ColdFusion 11 versions Update 13 and earlier
Description The issue is related to an exploitable Unsafe XML External Entity Processing. Successful exploitation could lead to information disclosure.
Recommendations For Adobe ColdFusion versions Update 5 and earlier, update to a version later than Update 5. For Adobe ColdFusion 11 versions Update 13 and earlier, update to a version later than Update 13.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2018-4942

Affected Products

Coldfusion