CVE-2019-7091 is a critical deserialization of untrusted data vulnerability affecting Adobe ColdFusion versions Update 1 and earlier, Update 7 and earlier, and Update 15 and earlier. This flaw allows for arbitrary code execution with a CVSS score of 9.8, indicating a severe risk due to its network-based attack vector, low attack complexity, and no user interaction required. While not currently listed in CISA's KEV catalog, its high EPSS score and FAUCET Risk Score suggest a significant likelihood of exploitation, despite the lack of public exploit intelligence in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are limited, but Adobe has released security fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:11.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.