QID 378080

Date Published: 2023-03-15

QID 378080: Adobe ColdFusion Multiple Vulnerabilities (APSB23-25)

Adobe ColdFusion is an application for developing Web sites.
Adobe has released security updates for ColdFusion versions 2021 and 2018..

Affected Products: ColdFusion (2021 release) Update 5 and earlier versions.
ColdFusion (2018 release) Update 15 and earlier versions.

QID Detection Logic (Authenticated):
This QID checks to see if Adobe ColdFusion and a .JAR file required to mitigate this update are installed.

Successful exploitation of these vulnerabilities could lead to arbitrary code execution and memory leak.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Adobe has released a fix to address this issue. Customers are advised to refer to APSB23-25 for updates pertaining to this vulnerability.

    CVEs related to QID 378080

    Software Advisories
    Advisory ID Software Component Link
    APSB23-25 URL Logo helpx.adobe.com/security/products/coldfusion/apsb23-25.html