PT-2021-4819 · Adobe · Coldfusion

CVE-2021-40698

·

Published

2021-09-14

·

Updated

2023-09-12

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2021 update 1 (and earlier) and versions 2018.10 (and earlier)
Description The issue is related to the use of inherently dangerous functions, which can lead to a security feature bypass. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment. The vulnerability allows a remote attacker to gain unauthorized access to protected information.
Recommendations For ColdFusion version 2021 update 1 and earlier, update to a version later than 2021 update 1 to resolve the issue. For ColdFusion version 2018.10 and earlier, update to a version later than 2018.10 to resolve the issue. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05547
CVE-2021-40698

Affected Products

Coldfusion