Description
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Related CPE's
a
adobe
coldfusion
28
References
https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html
PatchVendor Advisory
https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html
PatchVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2023-07-20T16:15:12.180
2 years agoLast modified
2025-01-23T17:53:45.997
10 months ago