CVE-2023-38206: ColdFusion | Improper Access Control (CWE-284)
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints resulting in a low-confidentiality impact. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Adobe ColdFusion vulnerability?
The vulnerability ID of this Adobe ColdFusion vulnerability is CVE-2023-38206.
What is the severity of the CVE-2023-38206 vulnerability?
The severity of the CVE-2023-38206 vulnerability is medium.
How does the CVE-2023-38206 vulnerability affect Adobe ColdFusion?
The CVE-2023-38206 vulnerability affects Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier).
What is the impact of the CVE-2023-38206 vulnerability?
The impact of the CVE-2023-38206 vulnerability is an improper access control vulnerability that could result in a security feature bypass.
How can I fix the CVE-2023-38206 vulnerability in Adobe ColdFusion?
To fix the CVE-2023-38206 vulnerability in Adobe ColdFusion, update to the latest version available.