CVE-2018-15964 is a use of a component with a known vulnerability affecting Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier. It carries a high CVSS score of 7.5, indicating a network-exploitable vulnerability with low attack complexity that could lead to significant information disclosure. While no public exploit code or active exploitation is reported, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.