RULE(RULE ID:336988)

Rule General Information
Release Date: 2022-08-22
Rule Name: Adobe ColdFusion Deserialization Vulnerability (CVE-2017-3066)
Severity:
CVE ID:
Rule Protection Details
Description: Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:98003
AdobeSecurityBulletins:apsb17-14
SecurityTrackerID:1038364
ExploitDB:43993
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html