PT-2021-4819 · Adobe · Coldfusion
Published
2021-09-14
·
Updated
2023-09-12
·
CVE-2021-40698
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ColdFusion versions 2021 update 1 (and earlier) and versions 2018.10 (and earlier)
Description
The issue is related to the use of inherently dangerous functions, which can lead to a security feature bypass. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment. The vulnerability allows a remote attacker to gain unauthorized access to protected information.
Recommendations
For ColdFusion version 2021 update 1 and earlier, update to a version later than 2021 update 1 to resolve the issue.
For ColdFusion version 2018.10 and earlier, update to a version later than 2018.10 to resolve the issue.
As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Coldfusion