QID 150716

Date Published: 2023-09-25

QID 150716: Adobe ColdFusion Access Control Bypass Vulnerability (CVE-2023-38205)

Adobe ColdFusion is an application server and a platform for building and deploying web and mobile applications.

Multiple versions of ColdFusion are affected by an Improper Access Control Vulnerability that could result in a Security feature bypass. Adobe has released security updates for ColdFusion versions 2023, 2021 and 2018.

Affected Products:
ColdFusion (2023 release) Update 2 and earlier versions.
ColdFusion (2021 release) Update 8 and earlier versions.
ColdFusion (2018 release) Update 18 and earlier versions.

QID Detection Logic (Unauthenticated):
This QID sends a specially crafted HTTP GET request to "CFIDE/wizards/common/utils.cfc" endpoint and based on the response confirms the vulnerability detection.

Successful exploitation of this vulnerability could allow an unauthenticated attacker to access the administration CFM and CFC endpoints.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as High - 7.8 severity.
  • Solution

    Adobe has released a fix to address this issue. Customers are advised to refer to APSB23-47 for updates pertaining to this vulnerability.

    CVEs related to QID 150716

    Software Advisories
    Advisory ID Software Component Link
    APSB23-47 URL Logo helpx.adobe.com/in/security/products/coldfusion/apsb23-47.html