CVE-2018-4942: XEE
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-4942?
CVE-2018-4942 is considered high severity due to its exploitable Unsafe XML External Entity Processing vulnerability.
How do I fix CVE-2018-4942?
To fix CVE-2018-4942, update your Adobe ColdFusion to the latest version available that includes the security patch.
What versions of Adobe ColdFusion are affected by CVE-2018-4942?
CVE-2018-4942 affects Adobe ColdFusion versions prior to Update 6, including ColdFusion 11 and 2016.
What could happen if CVE-2018-4942 is exploited?
Exploitation of CVE-2018-4942 could lead to information disclosure, potentially exposing sensitive data.
Is there a workaround for CVE-2018-4942?
There are no specific workarounds for CVE-2018-4942, and updating ColdFusion is the recommended action.