CVE-2019-8072 is a security bypass vulnerability affecting Adobe ColdFusion 2018 Update 4 and earlier, and ColdFusion 2016 Update 11 and earlier. This flaw could allow an unauthenticated attacker to achieve information disclosure in the context of the current user. With a CVSS score of 7.5 (High), it is easily exploitable over the network with low attack complexity, requiring no user interaction. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage, indicating awareness of the issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2016CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2016:update1:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2016:update10:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2016:update11:*:*:*:*:*:* | ||
2016CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2016:update2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.