CVE-2017-3066
CVE Published | 2017-04-27 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | adobe |
Related Product(s) | coldfusion |
Exploitation Reported (CISA KEV) | 2025-02-24 |
CVSS 3 Base Score | 9.8 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph