CyberSec.Space Logo
Back to CVE Browser

CVE-2017-3066

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score58.5850%
EPSS Percentile93.09th
PublishedApr 27, 2017
Last ModifiedApr 22, 2026

Vulnerability Description

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

Affected Platforms (CPE)

πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 10.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 11.0
πŸ“¦
Adobe

Coldfusion

= 2016
πŸ“¦
Adobe

Coldfusion

= 2016
πŸ“¦
Adobe

Coldfusion

= 2016
πŸ“¦
Adobe

Coldfusion

= 2016

References & Advisories

Related Vulnerabilities