CVE-2016-1115: Input Validation
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1115?
CVE-2016-1115 is rated as critical due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2016-1115?
To remediate CVE-2016-1115, apply the latest security updates provided by Adobe for ColdFusion.
What systems are affected by CVE-2016-1115?
CVE-2016-1115 affects Adobe ColdFusion versions 10 before Update 19, 11 before Update 8, and 2016 before Update 1.
What types of attacks can CVE-2016-1115 facilitate?
CVE-2016-1115 allows man-in-the-middle attackers to spoof servers using crafted X.509 certificates.
Are there any workarounds for CVE-2016-1115?
While applying updates is recommended, limiting exposure or using alternative secure configurations can serve as temporary workarounds.