Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for remote code execution. Required action: Apply updates per vendor instructions.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. Required action: Apply updates per vendor instructions.
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. Required action: Apply updates per vendor instructions.
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. Required action: Apply updates per vendor instructions.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution. Required action: Apply updates per vendor instructions.
Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution. Required action: Apply updates per vendor instructions.