QID 378671

Date Published: 2023-07-18

QID 378671: Adobe ColdFusion Arbitrary Code Execution Vulnerability (APSB23-41)

Adobe ColdFusion is an application for developing Web sites.
Adobe has released security updates for ColdFusion versions 2023,2021 and 2018.

Affected Products: ColdFusion (2021 release) Update 7 and earlier versions.
ColdFusion (2018 release) Update 17 and earlier versions.
ColdFusion (2023 release) Update 1 and earlier versions

QID Detection Logic (Authenticated):
This QID checks to see if Adobe ColdFusion and a .JAR file required to mitigate this update are installed.

Successful exploitation of this vulnerability could lead to arbitrary code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Adobe has released a fix to address this issue. Customers are advised to refer to APSB23-41 for updates pertaining to this vulnerability.

    CVEs related to QID 378671

    Software Advisories
    Advisory ID Software Component Link
    APSB23-41 URL Logo helpx.adobe.com/security/products/coldfusion/apsb23-41.html