RULE(RULE ID:713009)

Rule General Information
Release Date: 2019-07-22
Rule Name: Adobe ColdFusion Remote Code Execution Vulnerability (CVE-2019-7839)
Severity:
CVE ID:
Rule Protection Details
Description: ColdFusion versions Update 3 and earlier, Update 10 and earlier, and Update 18 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: AdobeSecurityBulletins:apsb19-27
http://packetstormsecurity.com/files/153439/Coldfusion-JNBridge-Remote-Code-Execution.html
https://seclists.org/bugtraq/2019/Jun/38
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://helpx.adobe.com/security/products/coldfusion/apsb19-27.html