CVE-2021-40699

ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*

History

21 Nov 2024, 06:24

Type Values Removed Values Added
References () https://helpx.adobe.com/security/products/coldfusion/apsb21-75.html - Vendor Advisory () https://helpx.adobe.com/security/products/coldfusion/apsb21-75.html - Vendor Advisory

12 Sep 2023, 11:56

Type Values Removed Values Added
First Time Adobe
Adobe coldfusion
References (MISC) https://helpx.adobe.com/security/products/coldfusion/apsb21-75.html - (MISC) https://helpx.adobe.com/security/products/coldfusion/apsb21-75.html - Vendor Advisory
CWE CWE-284 NVD-CWE-Other
CPE cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*:*

07 Sep 2023, 13:42

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-07 13:15

Updated : 2024-11-21 06:24


NVD link : CVE-2021-40699

Mitre link : CVE-2021-40699

CVE.ORG link : CVE-2021-40699


JSON object : View

Products Affected

adobe

  • coldfusion
CWE
CWE-284

Improper Access Control

NVD-CWE-Other