Junglewise Threat Intelligence

CVE-2018-4939: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVE-2018-4939 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion contains a deserialization of untrusted data vulnerability (CWE-502) that allows for arbitrary code execution. The vulnerability affects ColdFusion 2016 Update 5 and earlier, as well as ColdFusion 11 Update 13 and earlier.

Affected products

  • Adobe ColdFusion 2016 Update 5 and earlier versions
  • Adobe ColdFusion 11 Update 13 and earlier versions

Timeline

  • 2018-04-10: advisory: Adobe APSB18-14 advisory published
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed: NVD publication date

Related threats