CVE-2023-26347
CVE-2023-38205 issues | ColdFusion Admin Panel Access
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Las versiones 2023.5 (y anteriores) y 2021.11 (y anteriores) de Adobe ColdFusion se ven afectadas por una vulnerabilidad de control de acceso inadecuado que podría provocar una omisión de la función de seguridad. Un atacante no autenticado podría aprovechar esta vulnerabilidad para acceder a los endpoints de administración CFM y CFC. La explotación de este problema no requiere la interacción del usuario.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-02-22 CVE Reserved
- 2023-11-17 CVE Published
- 2024-07-16 EPSS Updated
- 2024-10-21 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html | 2023-11-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | < 2021 Search vendor "Adobe" for product "Coldfusion" and version " < 2021" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update10 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update11 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update6 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update7 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update9 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update5 |
Affected
|