Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
2023-07-12T16:15:11.623
2025-02-13T17:33:46.233
Analyzed
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2018 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2021 | Yes |
Application | adobe | coldfusion | 2023 | Yes |