Get the App
SLTechnology News&Howtos  ›  Network Security  › 

How to analyze the vulnerabilities of Adobe ColdFusion RCE CVE-2019-7839

Shulou Source: shulou.com Published: 2022-05-31 19:43:57 10月03日 Update

This article introduces how to analyze the vulnerabilities of Adobe ColdFusion RCE CVE-2019-7839. The content is very detailed. Interested friends can use it for reference. I hope it will be helpful to you.

Brief introduction of vulnerabilities

Adobe ColdFusion is a commercial rapid development platform. It can be used as a development platform, can also provide Flash remote services or as a background server for Adobe Flex applications.

On June 11, 2019, Adobe issued a security bulletin [1], fixing a number of serious vulnerabilities in Adobe ColdFusion. There is a command injection vulnerability submitted by Moritz Bechler (CVE-2019-7839).

On June 26th, 2019, Moritz Bechler published some details of the remote code execution vulnerability (CVE-2019-7839) on Bugtraq [2]. Due to defects in the JNBridge component, ColdFusion turned on the JNBridge component by default, resulting in code execution vulnerabilities.

Vulnerability impact

ColdFusion 2018 Update 3 and previous versions

ColdFusion 2018 Update 10 and earlier

ColdFusion 11 Update 18 and previous versions

Tags: Vulnerabilities runs versions services code differences success platforms projects vulnerability analysis analysis commands clients clients ports monitoring content parameters tools development platform Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology macOS Docker Linux Shulou Tech Info