Lucene search

K
cisa_kevCISACISA-KEV-CVE-2023-26360
HistoryMar 15, 2023 - 12:00 a.m.

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

2023-03-1500:00:00
CISA
www.cisa.gov
42
adobe coldfusion
deserialization
untrusted data
remote code execution
vulnerability

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0.965

Percentile

99.6%

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution.

CVSS3

8.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

EPSS

0.965

Percentile

99.6%