According to the vulnerability report released on 20th of July; Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability which could result in Arbitrary code execution.
 
                            Exploitation of this issue does not require user interaction. (CVE-2023-38203)
Affected Systems
                                Configuration 1 
                                cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update15:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update16:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update17:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update6:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2021:update7:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* 
                                cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:* 
                            
IoC’s
-
Recommended Solution(s)
-
Mitigations
-
CVE / CWE
CVE-2023-38203
Related Website(s)
* Vulnerabilities with a CVSS 3.1 score between 7.0 and 8.9 are evaluated to be “high” whereas vulnerabilities with a CVSS 3.1 score between 9.0 and 10.0 are evaluated to be “critical”.
+90 216 504 53 32
Aydınevler Mahallesi,İsmet İnönü Cadddesi,Küçükyalı Ofis Park A Blok,No:20/1 Maltepe İstanbul
+90 312 235 44 51
You can register to our newsletter on the home page to be instantly informed about security vulnerabilities.