CVE-2014-0572Adobe Coldfusion vulnerability

CWE-2643 documents3 sources
Severity
4.6MEDIUMNVD
EPSS
0.2%
top 60.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15
Latest updateMay 13

Description

Adobe ColdFusion 9.0 before Update 13, 9.0.1 before Update 12, 9.0.2 before Update 7, 10 before Update 14, and 11 before Update 2 allows local users to bypass intended IP-based access restrictions via unspecified vectors.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages1 packages

NVDadobe/coldfusion5 versions+4

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rwj3-r732-4w37: Adobe ColdFusion 92022-05-13
CVEList
CVE-2014-0572: Adobe ColdFusion 92014-10-15
CVE-2014-0572 — Adobe Coldfusion vulnerability | cvebase