CVE-2016-1114Deserialization of Untrusted Data in Adobe Coldfusion

Severity
9.8CRITICALNVD
EPSS
2.3%
top 15.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 13

Description

Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDadobe/coldfusion10.0, 11.0, 2016+2

🔴Vulnerability Details

2
GHSA
GHSA-g699-7w89-8ppm: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted2022-05-13
CVEList
CVE-2016-1114: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted2016-05-11
CVE-2016-1114 — Deserialization of Untrusted Data | cvebase