Vulnerability Description
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Coldfusion | < 2018 |
Related Weaknesses (CWE)
References
- https://helpx.adobe.com/security/products/coldfusion/apsb21-75.htmlVendor Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb21-75.htmlVendor Advisory
FAQ
What is CVE-2021-40699?
CVE-2021-40699 is a vulnerability with a CVSS score of 7.4 (HIGH). ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated...
How severe is CVE-2021-40699?
CVE-2021-40699 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-40699?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Coldfusion.