PT-2021-5083 · Adobe · Coldfusion

Published

2021-09-14

·

Updated

2023-09-12

·

CVE-2021-40699

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2021 update 1 and earlier ColdFusion versions 2018.10 and earlier
Description The issue is related to improper access control in ColdFusion, specifically when checking permissions in the CFIDE path. This could allow an authenticated attacker to access and manipulate arbitrary data on the environment. The vulnerability is associated with deficiencies in access control, which can be exploited by a remote attacker to bypass existing security restrictions and gain unauthorized access to protected information.
Recommendations For ColdFusion version 2021 update 1 and earlier, update to a version later than 2021 update 1 to resolve the issue. For ColdFusion versions 2018.10 and earlier, update to a version later than 2018.10 to resolve the issue. As a temporary workaround, consider restricting access to the CFIDE path to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05864
CVE-2021-40699

Affected Products

Coldfusion