7.4
CVE-2021-40698
- EPSS 0.54%
- Veröffentlicht 07.09.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:24:35
- Erkennungen
ColdFusion Use of Inherently Dangerous Function Leads To Security feature bypass
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an Use of Inherently Dangerous Function vulnerability that can lead to a security feature bypass . An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version < 2018
Adobe ≫ Coldfusion Version 2018 Update -
Adobe ≫ Coldfusion Version 2018 Update update1
Adobe ≫ Coldfusion Version 2018 Update update10
Adobe ≫ Coldfusion Version 2018 Update update2
Adobe ≫ Coldfusion Version 2018 Update update3
Adobe ≫ Coldfusion Version 2018 Update update4
Adobe ≫ Coldfusion Version 2018 Update update5
Adobe ≫ Coldfusion Version 2018 Update update6
Adobe ≫ Coldfusion Version 2018 Update update7
Adobe ≫ Coldfusion Version 2018 Update update8
Adobe ≫ Coldfusion Version 2018 Update update9
Adobe ≫ Coldfusion Version 2021 Update -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.54% | 0.409 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.4 | 3.1 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
|
| Adobe | 7.4 | 3.1 | 3.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
|
CWE-242 Use of Inherently Dangerous Function
The product calls a function that can never be guaranteed to work safely.
https://helpx.adobe.com/security/products/coldfusion/apsb21-75.html