QID 375398
Date Published: 2021-03-24
QID 375398: Adobe ColdFusion Code Execution Vulnerability (APSB21-16)
Adobe ColdFusion is an application for developing Web sites. These updates resolve a critical vulnerability that could lead to arbitrary code execution
Affected Versions:
Adobe ColdFusion (2016 Release) Update 16 and earlier version
Adobe ColdFusion (2018 Release) Update 10 and earlier version
ColdFusion 2021 Version 2021.0.0.323925
QID Detection Logic (Authenticated):
This QID checks to see if Adobe ColdFusion and a .JAR file required to mitigate this update are installed.
QID Detection Logic (Un-Authenticated):
The QID checks for the vulnerable version from "CFIDE/adminapi/administrator.cfc?method=getBuildNumber"
An attacker could exploit this vulnerability to execute arbitrary code.
Adobe has released a fix to address this issue. Customers are advised to refer to APSB21-16 for updates pertaining to this vulnerability.
CVEs related to QID 375398
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB21-16 |
|