Junglewise Threat Intelligence

CVE-2023-38205: Adobe ColdFusion Improper Access Control Vulnerability

CVE-2023-38205 · Severity: critical · CVSS 7.5 · Exploited in the wild · Published 2023-07-20

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to improper access control, allowing an unauthenticated attacker to bypass security features. This vulnerability enables access to sensitive administration CFM and CFC endpoints without requiring user interaction.

Affected products

  • Adobe ColdFusion 2018u18 and earlier, 2021u8 and earlier, 2023u2 and earlier

Timeline

  • 2023-07-20: disclosed: Initial publication date and addition to CISA KEV catalog.
  • 2023-07-20: kev added: Added to CISA Known Exploited Vulnerabilities catalog.
  • 2023-09-14: advisory: NVD Published Date.

Related threats