← back
CVE-2021-40699highCWE-284

ColdFusion CFIDE Improper Access Control Leads To Privilege Escalation

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.4epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
ColdFusion version 2021 update 1 (and earlier) and versions 2018.10 (and earlier) are impacted by an improper access control vulnerability when checking permissions in the CFIDE path. An authenticated attacker could leverage this vulnerability to access and manipulate arbitrary data on the environment.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected products
Adobe · ColdFusion