CVE-2020-3794: Critical severity Adobe ColdFusion vulnerability
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3794?
The severity of CVE-2020-3794 is critical with a CVSS score of 9.8.
Which versions of ColdFusion are affected by CVE-2020-3794?
ColdFusion versions 2016 and ColdFusion 2018 are affected by CVE-2020-3794.
What is the impact of CVE-2020-3794?
Successful exploitation of CVE-2020-3794 could lead to arbitrary code execution of files located in the webroot or its subdirectory.
How can I fix CVE-2020-3794?
Apply the appropriate security update or patch provided by Adobe to mitigate the vulnerability in ColdFusion 2016 and ColdFusion 2018.
Where can I find more information about CVE-2020-3794?
You can find more information about CVE-2020-3794 on the Adobe website at https://helpx.adobe.com/security/products/coldfusion/apsb20-16.html.