Sat.Jul 15, 2023 - Fri.Jul 21, 2023

Remove category
article thumbnail

Adobe warns customers of a critical ColdFusion RCE exploited in attacks

Security Affairs

Adobe addressed a total of three vulnerabilities in ColdFusion, below the complete list of fixed issues: Vulnerability Details Vulnerability Category Vulnerability Impact Severity CVSS base score  CVSS vector CVE Numbers Improper Access Control ( CWE-284 ) Security feature bypass   Critical 7.5

article thumbnail

Adobe out-of-band update addresses an actively exploited ColdFusion zero-day

Security Affairs

The vulnerabilities could lead to arbitrary code execution and security feature bypass. AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2023-38204 Improper Access Control ( CWE-284 ) Security feature bypass Critical 7.5 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2023-38205 Improper Access Control ( CWE-284 ) Security feature bypass Moderate 5.3