7.5
CVE-2023-26347
- EPSS 86.56%
- Veröffentlicht 17.11.2023 14:15:20
- Zuletzt bearbeitet 21.11.2024 07:51:10
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version < 2021
Adobe ≫ Coldfusion Version2021 Update-
Adobe ≫ Coldfusion Version2021 Updateupdate1
Adobe ≫ Coldfusion Version2021 Updateupdate10
Adobe ≫ Coldfusion Version2021 Updateupdate11
Adobe ≫ Coldfusion Version2021 Updateupdate2
Adobe ≫ Coldfusion Version2021 Updateupdate3
Adobe ≫ Coldfusion Version2021 Updateupdate4
Adobe ≫ Coldfusion Version2021 Updateupdate5
Adobe ≫ Coldfusion Version2021 Updateupdate6
Adobe ≫ Coldfusion Version2021 Updateupdate7
Adobe ≫ Coldfusion Version2021 Updateupdate8
Adobe ≫ Coldfusion Version2021 Updateupdate9
Adobe ≫ Coldfusion Version2023 Update-
Adobe ≫ Coldfusion Version2023 Updateupdate1
Adobe ≫ Coldfusion Version2023 Updateupdate2
Adobe ≫ Coldfusion Version2023 Updateupdate3
Adobe ≫ Coldfusion Version2023 Updateupdate4
Adobe ≫ Coldfusion Version2023 Updateupdate5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 86.56% | 0.994 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@adobe.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.