CVE-2017-11286: XEE
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11286?
CVE-2017-11286 is rated as a crucial vulnerability due to its potential for XML external entity (XXE) injection.
How do I fix CVE-2017-11286?
To fix CVE-2017-11286, upgrade to Adobe ColdFusion 2016 Update 5 or later, or ColdFusion 11 Update 13 or later.
Which versions of Adobe ColdFusion are affected by CVE-2017-11286?
CVE-2017-11286 affects Adobe ColdFusion 2016 Update 4 and earlier, as well as ColdFusion 11 Update 12 and earlier versions.
What is an XML external entity (XXE) injection vulnerability in the context of CVE-2017-11286?
In the context of CVE-2017-11286, an XML external entity (XXE) injection vulnerability allows an attacker to interfere with the processing of XML data, leading to potential data exposure or system compromise.
Can CVE-2017-11286 be exploited remotely?
Yes, CVE-2017-11286 can be exploited remotely if an attacker is able to send malicious XML data to the vulnerable Adobe ColdFusion application.