Short Name |
APP:MISC:ADOBE-COLDFUSION-RCE |
---|---|
Severity |
Major |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Adobe ColdFusion RMI Registry Insecure Deserialization Remote Code Execution |
Release Date |
2017/11/07 |
Update Number |
3003 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
An insecure deserialization vulnerability has been reported in the Flex integration service of Adobe ColdFusion. A remote, unauthenticated attacker can exploit this vulnerability by sending maliciously crafted serialized data to the target application. Successful exploitation could result in arbitrary code execution in the context of SYSTEM.
Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.