CVE-2023-38206Improper Access Control in Adobe Coldfusion

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 73.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14

Description

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints resulting in a low-confidentiality impact. Exploitation of this issue does not require user interaction.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5adobe/coldfusioncf2023U2
NVDadobe/coldfusion2018, 2021, 2023+2

🔴Vulnerability Details

2
CVEList
ColdFusion | Improper Access Control (CWE-284)2023-09-14
GHSA
GHSA-m7q8-m2mr-jg5g: Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerabilit2023-09-14
CVE-2023-38206 — Improper Access Control in Adobe | cvebase