QID 379500
Date Published: 2024-03-13
QID 379500: Adobe ColdFusion Arbitrary File Read Vulnerability (APSB24-14)
Adobe ColdFusion is an application for developing Web sites.
Adobe has released security updates for ColdFusion versions 2023 and 2021.
Affected Products:
ColdFusion (2021 release) Update 12 and earlier versions
ColdFusion (2023 release) Update 6 and earlier versions
QID Detection Logic:
Authenticated:
Windows: This QID checks to see if Adobe ColdFusion and a .JAR file required to mitigate this update are installed.
Unauthenticated:
This QID checks for installed build version of Adobe ColdFusion using endpoint "/CFIDE/adminapi/administrator.cfc?method=getBuildNumber".
Successful exploitation of this vulnerability may allow an unauthenticated attacker to read arbitrary files from the target system.
Adobe has released a fix to address this issue. Customers are advised to refer to APSB24-14 for updates pertaining to this vulnerability.
CVEs related to QID 379500
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| APSB24-14 |
|