Vulnerability Details CVE-2018-4939
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.77
EPSS Ranking 98.9%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Proposed Action
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.
Ransomware Campaign
Unknown
Products affected by CVE-2018-4939
-
cpe:2.3:a:adobe:coldfusion:11.0
-
cpe:2.3:a:adobe:coldfusion:2016