« Volver al listado

CVE-2018-15961

Estado: AnalizadaCrítica (9.8)⚠ Explotación activa

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CISA KEV — explotada activamente

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-15961",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2018-15961",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "active"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-04T15:24:53.847806Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@adobe.com",
      "affectedData": [
        {
          "vendor": "Adobe",
          "product": "ColdFusion",
          "versions": [
            {
              "status": "affected",
              "version": "July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier versions"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-09-25T13:29:01.567",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/105314",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securitytracker.com/id/1041621",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "https://www.exploit-db.com/exploits/45979/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "psirt@adobe.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/105314",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id/1041621",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://helpx.adobe.com/security/products/coldfusion/apsb18-33.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/45979/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-15961",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-434"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution."
    },
    {
      "lang": "es",
      "value": "Adobe ColdFusion en versiones 12 de julio (2018.0.0.310739), Update 6 y anteriores, y Update 14 y anteriores, tiene una vulnerabilidad de subida de archivos sin restricción. La explotación con éxito de esta vulnerabilidad podría permitir la ejecución arbitraria de código."
    }
  ],
  "lastModified": "2026-06-17T01:43:25.060",
  "cisaActionDue": "2022-05-03",
  "cisaExploitAdd": "2021-11-03",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E217CE63-07DC-4A88-8877-181F33A21C20"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D4BD25E-6856-40EC-98A8-ACB540992487"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F0907E8-7BC4-4F5A-894C-B7C5F6BAAEAE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFE18FEA-271A-42FE-8C24-19731DEB5444"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update12:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15F7DCF1-D9F2-45C0-B089-E37C91579729"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update13:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB398297-DA76-4A56-858B-FC69FF220DAF"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update14:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBC72CEF-D09E-4AD8-98CD-1EE0B5CB62A2"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82F81CF8-1482-4731-AD34-677B8D6B930B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57BBBE71-BBE0-4129-B997-3F9AF54BFBD8"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E514D95-9287-4A43-9A44-BD6F8EDC5DA8"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "96C50CD1-CE75-4D70-AD65-2DB6027D806A"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE1B1190-4699-4FB0-AD46-DF0233B5BA90"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "827CB550-5078-4FD5-8B1F-616C06912AD9"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "31F22450-F26C-4797-9292-66CA444C0D2C"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72450205-B4F4-4B44-9991-F4876D829BBD"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B262F442-FF7F-4CC0-A9C5-FFD0EDB08E38"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F3D7C8E-6695-44DF-AC9A-1AE09C46C529"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12BAE66C-A745-4661-B5BB-7FC2C169CC82"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E6EC92F3-1EF8-4820-9CD8-ECEA03D27A7B"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7446D70-D616-4EC1-BC64-41CDE56EFEAE"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59453B01-EAAF-4291-B2C2-98835F5AFE80"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2016:update6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63076ED8-FC30-40B1-99A7-D0069423A536"
            },
            {
              "criteria": "cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3B54B2B0-B1E1-4B4E-A529-D0BD3B5DEEF3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@adobe.com",
  "cisaRequiredAction": "Apply updates per vendor instructions.",
  "cisaVulnerabilityName": "Adobe ColdFusion Unrestricted File Upload Vulnerability"
}