QID 375398

Date Published: 2021-03-24

QID 375398: Adobe ColdFusion Code Execution Vulnerability (APSB21-16)

Adobe ColdFusion is an application for developing Web sites. These updates resolve a critical vulnerability that could lead to arbitrary code execution

Affected Versions:
Adobe ColdFusion (2016 Release) Update 16 and earlier version
Adobe ColdFusion (2018 Release) Update 10 and earlier version
ColdFusion 2021 Version 2021.0.0.323925

QID Detection Logic (Authenticated):
This QID checks to see if Adobe ColdFusion and a .JAR file required to mitigate this update are installed.

QID Detection Logic (Un-Authenticated):
The QID checks for the vulnerable version from "CFIDE/adminapi/administrator.cfc?method=getBuildNumber"

An attacker could exploit this vulnerability to execute arbitrary code.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Adobe has released a fix to address this issue. Customers are advised to refer to APSB21-16 for updates pertaining to this vulnerability.

    CVEs related to QID 375398

    Software Advisories
    Advisory ID Software Component Link
    APSB21-16 URL Logo helpx.adobe.com/security/products/coldfusion/apsb21-16.html