PT-2019-5913 · Adobe · Coldfusion

Published

2019-12-10

·

Updated

2021-07-21

·

CVE-2019-8256

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions Update 6 and earlier
Description The issue is related to errors in using standard permissions, specifically an insecure inherited permissions vulnerability of the default installation directory. This could allow an attacker to escalate their privileges.
Recommendations For Adobe ColdFusion versions Update 6 and earlier, update to a version later than Update 6 to resolve the issue. As a temporary workaround, consider restricting access to the default installation directory to minimize the risk of exploitation.

Fix

Incorrect Permission

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03787
CVE-2019-8256

Affected Products

Coldfusion