CVE-2019-7840: Critical severity adobe coldfusion vulnerability
ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-7840?
CVE-2019-7840 is a vulnerability in ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier, which allows for deserialization of untrusted data and could lead to arbitrary code execution.
What is the severity of CVE-2019-7840?
The severity of CVE-2019-7840 is critical with a CVSS score of 9.8.
What software versions are affected by CVE-2019-7840?
ColdFusion versions 11.0, 2016, and 2018 with various updates are affected by CVE-2019-7840.
How can CVE-2019-7840 be exploited?
CVE-2019-7840 can be exploited by an attacker utilizing deserialization of untrusted data to execute arbitrary code.
Is there a fix for CVE-2019-7840?
Yes, Adobe has released security updates to address CVE-2019-7840. It is recommended to upgrade to the latest version of ColdFusion to mitigate this vulnerability.