CVE-2016-1115Improper Input Validation in Adobe Coldfusion

Severity
5.9MEDIUMNVD
EPSS
2.5%
top 14.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 13

Description

Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which might allow man-in-the-middle attackers to spoof servers via a crafted certificate.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages1 packages

NVDadobe/coldfusion10.0, 11.0, 2016+2

🔴Vulnerability Details

2
GHSA
GHSA-fr3r-r4pg-fc5c: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X2022-05-13
CVEList
CVE-2016-1115: Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X2016-05-11
CVE-2016-1115 — Improper Input Validation in Adobe | cvebase