First published: Wed Mar 25 2020(Updated: )
ColdFusion versions ColdFusion 2016, and ColdFusion 2018 have a file inclusion vulnerability. Successful exploitation could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2016 | |
Adobe ColdFusion | =2016-update1 | |
Adobe ColdFusion | =2016-update10 | |
Adobe ColdFusion | =2016-update11 | |
Adobe ColdFusion | =2016-update12 | |
Adobe ColdFusion | =2016-update13 | |
Adobe ColdFusion | =2016-update2 | |
Adobe ColdFusion | =2016-update3 | |
Adobe ColdFusion | =2016-update4 | |
Adobe ColdFusion | =2016-update5 | |
Adobe ColdFusion | =2016-update6 | |
Adobe ColdFusion | =2016-update7 | |
Adobe ColdFusion | =2016-update8 | |
Adobe ColdFusion | =2016-update9 | |
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2018-update1 | |
Adobe ColdFusion | =2018-update2 | |
Adobe ColdFusion | =2018-update3 | |
Adobe ColdFusion | =2018-update4 | |
Adobe ColdFusion | =2018-update5 | |
Adobe ColdFusion | =2018-update6 | |
Adobe ColdFusion | =2018-update7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-3794 is critical with a CVSS score of 9.8.
ColdFusion versions 2016 and ColdFusion 2018 are affected by CVE-2020-3794.
Successful exploitation of CVE-2020-3794 could lead to arbitrary code execution of files located in the webroot or its subdirectory.
Apply the appropriate security update or patch provided by Adobe to mitigate the vulnerability in ColdFusion 2016 and ColdFusion 2018.
You can find more information about CVE-2020-3794 on the Adobe website at https://helpx.adobe.com/security/products/coldfusion/apsb20-16.html.