Adobe.ColdFusion.OOXML.XXE.Information.Disclosure

description-logoDescription

This indicates an attack attempt against an Information Disclousre vulnerability in Adobe ColdFusion.
The vulnerability is due to insufficient validation in the the Office Open XML (OOXML) component, when parsing an XML external entity (XXE). A remote attacker may be able to read arbitrary files in the targeted system via a crafted OOXML document.

affected-products-logoAffected Products

Adobe Systems ColdFusion 11 prior to Update 10
Adobe Systems ColdFusion 10 prior to Update 21

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://helpx.adobe.com/security/products/coldfusion/apsb16-30.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

References

APSB16-30