Adobe ColdFusion 10 before Update 19, 11 before Update 8,...
Critical severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
May 11, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Feb 1, 2023
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
References