CVE-2023-38206
ColdFusion | Improper Access Control (CWE-284)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints resulting in a low-confidentiality impact. Exploitation of this issue does not require user interaction.
Las versiones 2018u18 (y anteriores), 2021u8 (y anteriores) y 2023u2 (y anteriores) de Adobe ColdFusion se ven afectadas por una vulnerabilidad de Control de Acceso Inadecuado que podría provocar una omisión de la función Seguridad. Un atacante podría aprovechar esta vulnerabilidad para acceder a los endpoints de administración CFM y CFC, lo que tendría un impacto de baja confidencialidad. La explotación de este problema no requiere la interacción del usuario.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-13 CVE Reserved
- 2023-09-14 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html | 2023-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update10 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update11 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update12 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update13 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update14 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update15 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update16 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update18 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update6 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update7 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2018 Search vendor "Adobe" for product "Coldfusion" and version "2018" | update9 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update2 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update3 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update4 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update5 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update6 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update7 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2021 Search vendor "Adobe" for product "Coldfusion" and version "2021" | update8 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update1 |
Affected
| ||||||
Adobe Search vendor "Adobe" | Coldfusion Search vendor "Adobe" for product "Coldfusion" | 2023 Search vendor "Adobe" for product "Coldfusion" and version "2023" | update2 |
Affected
|