TROYANOSYVIRUS
Volver a CVEs

CVE-2018-4939

CRITICALCISA KEV
9.8

Descripcion

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

Detalles CVE

Puntuacion CVSS v3.19.8
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado5/19/2018
Ultima modificacion10/23/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorAdobe
ProductoColdFusion
Nombre vulnerabilidadAdobe ColdFusion Deserialization of Untrusted Data Vulnerability
Fecha inclusion KEV2021-11-03
Fecha limite remediacion2022-05-03
Uso en ransomwareUnknown

Productos afectados

adobe:coldfusion

Debilidades (CWE)

CWE-502CWE-502

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.