Executive brief
Adobe ColdFusion is vulnerable to deserialization of untrusted data. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the server without any user interaction.
Affected products
- Adobe ColdFusion 2018u16 and earlier, 2021u6 and earlier, 2023.0.0.330468 and earlier
Timeline
- 2023-07-20: disclosed: Initial NVD analysis date
- 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog