CVE-2017-3066
27.04.2017, 14:59
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.Enginsight
Vendor | Product | Version |
---|---|---|
adobe | coldfusion | 10.0 |
adobe | coldfusion | 10.0:update1 |
adobe | coldfusion | 10.0:update10 |
adobe | coldfusion | 10.0:update11 |
adobe | coldfusion | 10.0:update12 |
adobe | coldfusion | 10.0:update13 |
adobe | coldfusion | 10.0:update14 |
adobe | coldfusion | 10.0:update15 |
adobe | coldfusion | 10.0:update16 |
adobe | coldfusion | 10.0:update17 |
adobe | coldfusion | 10.0:update18 |
adobe | coldfusion | 10.0:update19 |
adobe | coldfusion | 10.0:update2 |
adobe | coldfusion | 10.0:update20 |
adobe | coldfusion | 10.0:update21 |
adobe | coldfusion | 10.0:update22 |
adobe | coldfusion | 10.0:update3 |
adobe | coldfusion | 10.0:update4 |
adobe | coldfusion | 10.0:update5 |
adobe | coldfusion | 10.0:update6 |
adobe | coldfusion | 10.0:update7 |
adobe | coldfusion | 10.0:update8 |
adobe | coldfusion | 10.0:update9 |
adobe | coldfusion | 11.0 |
adobe | coldfusion | 11.0:update1 |
adobe | coldfusion | 11.0:update10 |
adobe | coldfusion | 11.0:update11 |
adobe | coldfusion | 11.0:update2 |
adobe | coldfusion | 11.0:update3 |
adobe | coldfusion | 11.0:update4 |
adobe | coldfusion | 11.0:update5 |
adobe | coldfusion | 11.0:update6 |
adobe | coldfusion | 11.0:update7 |
adobe | coldfusion | 11.0:update8 |
adobe | coldfusion | 11.0:update9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References