CVE-2021-40699

Published Sep 7, 2023

Last updated 5 months ago

Overview

Description
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
Source
psirt@adobe.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
7.4
Impact score
3.7
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Severity
HIGH

Weaknesses

psirt@adobe.com
CWE-284
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations