Information disclosure in ColdFusion - CVE-2016-4264

 

Information disclosure in ColdFusion - CVE-2016-4264

Published: September 7, 2016 / Updated: September 14, 2018


Vulnerability identifier: #VU366
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4264
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows attackers to gain access to potentially sensitive data.

The vulnerability exists due to flaw in XML objects analysis engine. A remote attacker supply specially crafted XML data and obtain potentilally sensitive information.

Successful exploitation of this vulnerability will allow an attacker to obtain sensitive information.


Affected software

ColdFusion

How to mitigate CVE-2016-4264



Links to Public Exploits and PoC-codes

External References

Related Security Bulletins