Total vulnerabilities in the database
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Software | From | Fixed in |
---|---|---|
adobe / coldfusion | 2021 | 2021.x |
adobe / coldfusion | 2021-update1 | 2021-update1.x |
adobe / coldfusion | 2021-update2 | 2021-update2.x |
adobe / coldfusion | 2021-update3 | 2021-update3.x |
adobe / coldfusion | 2021-update4 | 2021-update4.x |
adobe / coldfusion | 2021-update5 | 2021-update5.x |
adobe / coldfusion | 2021-update6 | 2021-update6.x |
adobe / coldfusion | 2021-update7 | 2021-update7.x |
adobe / coldfusion | 2023-update1 | 2023-update1.x |
adobe / coldfusion | 2023 | 2023.x |
adobe / coldfusion | 2023-update2 | 2023-update2.x |
adobe / coldfusion | 2021-update8 | 2021-update8.x |
adobe / coldfusion | 2021-update9 | 2021-update9.x |
adobe / coldfusion | 2021-update10 | 2021-update10.x |
adobe / coldfusion | 2021-update11 | 2021-update11.x |
adobe / coldfusion | - | 2021 |
adobe / coldfusion | 2023-update3 | 2023-update3.x |
adobe / coldfusion | 2023-update4 | 2023-update4.x |
adobe / coldfusion | 2023-update5 | 2023-update5.x |