vendor:
Adobe ColdFusion
by:
Amel BOUZIANE-LEBLOND
7.5
CVSS
HIGH
LDAP Java Object Deserialization Remote Code Execution
CWE
Product Name: Adobe ColdFusion
Affected Version From: Adobe Coldfusion 11.0.03.292866
Affected Version To: Adobe Coldfusion 11
Patch Exists: NO
Related CWE:
CPE: a:adobe:coldfusion:11.0.03.292866
Platforms Tested: Microsoft Windows Server, Linux
2022
Adobe ColdFusion 11 – LDAP Java Object Deserialization Remote Code Execution (RCE)
ColdFusion allows an unauthenticated user to connect to any LDAP server. An attacker can exploit it to achieve remote code execution. JNDI attack via the 'verifyldapserver' parameter on the utils.cfc.
Mitigation:
Apply the necessary security patches or updates provided by Adobe. Restrict access to the ColdFusion server from untrusted networks. Monitor network traffic for any suspicious activity.