ColdFusion versions Update 6 and earlier have an insecure inherited permissions of default installation directory vulnerability. Successful exploitation could lead to privilege escalation.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-8256
Reference (s):
- https://helpx.adobe.com/security/products/coldfusion/apsb19-58.html