Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2023-38203

Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

  • Published: Jul 20, 2023
  • Updated: Jul 21, 2023
  • CVE: CVE-2023-38203
  • Severity: Critical
  • Exploit:

CVSS v3:

  • Severity: Critical
  • Score: 9.8
  • AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Software From Fixed in
adobe / coldfusion 2018 2018.x
adobe / coldfusion 2018-update1 2018-update1.x
adobe / coldfusion 2018-update2 2018-update2.x
adobe / coldfusion 2018-update3 2018-update3.x
adobe / coldfusion 2018-update4 2018-update4.x
adobe / coldfusion 2018-update5 2018-update5.x
adobe / coldfusion 2018-update6 2018-update6.x
adobe / coldfusion 2018-update7 2018-update7.x
adobe / coldfusion 2018-update8 2018-update8.x
adobe / coldfusion 2018-update9 2018-update9.x
adobe / coldfusion 2018-update10 2018-update10.x
adobe / coldfusion 2021 2021.x
adobe / coldfusion 2021-update1 2021-update1.x
adobe / coldfusion 2021-update2 2021-update2.x
adobe / coldfusion 2021-update3 2021-update3.x
adobe / coldfusion 2018-update13 2018-update13.x
adobe / coldfusion 2018-update12 2018-update12.x
adobe / coldfusion 2018-update11 2018-update11.x
adobe / coldfusion 2021-update4 2021-update4.x
adobe / coldfusion 2018-update14 2018-update14.x
adobe / coldfusion 2021-update5 2021-update5.x
adobe / coldfusion 2018-update15 2018-update15.x
adobe / coldfusion 2018-update16 2018-update16.x
adobe / coldfusion 2021-update6 2021-update6.x
adobe / coldfusion 2021-update7 2021-update7.x
adobe / coldfusion 2023-update1 2023-update1.x
adobe / coldfusion 2023 2023.x
adobe / coldfusion 2018-update17 2018-update17.x