CVE-2018-4942

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
adobeCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
adobecoldfusion
11.0
adobecoldfusion
11.0:update1
adobecoldfusion
11.0:update10
adobecoldfusion
11.0:update11
adobecoldfusion
11.0:update12
adobecoldfusion
11.0:update13
adobecoldfusion
11.0:update2
adobecoldfusion
11.0:update3
adobecoldfusion
11.0:update4
adobecoldfusion
11.0:update5
adobecoldfusion
11.0:update6
adobecoldfusion
11.0:update7
adobecoldfusion
11.0:update8
adobecoldfusion
11.0:update9
𝑥
= Vulnerable software versions