CVE-2023-38205: Adobe ColdFusion Improper Access Control Vulnerability
Adobe ColdFusion contains an improper access control vulnerability that allows for a security feature bypass.
Other sources
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Apply mitigations per vendor instructions for Adobe ColdFusion. If vendor mitigations are unavailable, discontinue use of Adobe ColdFusion. Affected versions: 2018u18 (and earlier), 2021u8 (and earlier), 2023u2 (and earlier).
Event History
Frequently Asked Questions
What is the vulnerability ID of this Adobe ColdFusion vulnerability?
The vulnerability ID is CVE-2023-38205.
What is the severity of CVE-2023-38205?
The severity of CVE-2023-38205 is high with a severity value of 7.5.
Which versions of Adobe ColdFusion are affected by CVE-2023-38205?
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier), and 2023u2 (and earlier) are affected by CVE-2023-38205.
What is the impact of CVE-2023-38205?
CVE-2023-38205 can result in a security feature bypass, allowing an attacker to access the administration CFM and CFC endpoints.
Where can I find more information about CVE-2023-38205?
You can find more information about CVE-2023-38205 at the following reference: [link](https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html).