CVE-2018-4939: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
Other sources
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4939?
CVE-2018-4939 has a critical severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2018-4939?
To fix CVE-2018-4939, update Adobe ColdFusion to version 2016 update 6 or newer, or ColdFusion 11 update 14 or newer.
What products are affected by CVE-2018-4939?
CVE-2018-4939 affects Adobe ColdFusion versions 11.0 through 11.0-update13 and 2016 versions through 2016-update5.
What type of vulnerability is CVE-2018-4939?
CVE-2018-4939 is classified as a deserialization of untrusted data vulnerability.
What could happen if CVE-2018-4939 is exploited?
If exploited, CVE-2018-4939 could allow an attacker to execute arbitrary code on the affected system.