Vulnerability Name:
CVE-2019-8073 (CCN-167508)
Assigned:
2019-09-24
Published:
2019-09-24
Updated:
2020-09-04
Summary:
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.
CVSS v3 Severity:
9.8 Critical
(CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
)
8.5 High
(Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
8.8 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
)
7.7 High
(CCN Temporal CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
Required
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
High
Integrity (I):
High
Availibility (A):
High
CVSS v2 Severity:
10.0 High
(CVSS v2 Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
9.0 High
(CCN CVSS v2 Vector:
AV:N/AC:L/Au:S/C:C/I:C/A:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Low
Athentication (Au):
Single_Instance
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
Vulnerability Type:
CWE-77
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2019-8073
Source: XF
Type: UNKNOWN
adobe-coldfusion-cve20198073-code-exec(167508)
Source: CCN
Type: Adobe Security Bulletin APSB19-47
Security updates available for ColdFusion
Source: CONFIRM
Type: Vendor Advisory
https://helpx.adobe.com/security/products/coldfusion/apsb19-47.html
Vulnerable Configuration:
Configuration 1
:
cpe:/a:adobe:coldfusion:2016:-:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update1:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update10:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update11:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update2:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update3:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update4:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update5:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update6:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update7:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update8:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update9:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:-:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
Configuration CCN 1
:
cpe:/a:adobe:coldfusion:2016:update5:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update6:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update7:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update9:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update8:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update4:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update3:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update2:*:*:*:*:*:*
OR
cpe:/a:adobe:coldfusion:2016:update1:*:*:*:*:*:*
AND
cpe:/a:adobe:coldfusion:2016:update10:*:*:*:*:*:*
Denotes that component is vulnerable
BACK
adobe
coldfusion 2016 -
adobe
coldfusion 2016 update1
adobe
coldfusion 2016 update10
adobe
coldfusion 2016 update11
adobe
coldfusion 2016 update2
adobe
coldfusion 2016 update3
adobe
coldfusion 2016 update4
adobe
coldfusion 2016 update5
adobe
coldfusion 2016 update6
adobe
coldfusion 2016 update7
adobe
coldfusion 2016 update8
adobe
coldfusion 2016 update9
adobe
coldfusion 2018 -
adobe
coldfusion 2018 update1
adobe
coldfusion 2018 update2
adobe
coldfusion 2018 update3
adobe
coldfusion 2018 update4
adobe
coldfusion 2016 update_5
adobe
coldfusion 2016 update_6
adobe
coldfusion 2016 update_7
adobe
coldfusion 2018 update_1
adobe
coldfusion 2018 update_2
adobe
coldfusion 2016 update_9
adobe
coldfusion 2018 update_3
adobe
coldfusion 2016 update_8
adobe
coldfusion 2016 update_4
adobe
coldfusion 2016 update_3
adobe
coldfusion 2016 update_2
adobe
coldfusion 2016 update_1
adobe
coldfusion 2016 update_10