RULE(RULE ID:337623)

Rule General Information
Release Date: 2023-08-22
Rule Name: Adobe ColdFusion Deserialization Vulnerability (CVE-2023-29300)
Severity:
CVE ID:
Rule Protection Details
Description: Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Impact: An attacker can carefully construct malicious serialized data and pass it to the application, and execute the malicious code constructed by the attacker when the application deserializes the object.
Affected OS: Windows, Linux, Others
Reference: AdobeSecurityBulletins:apsb23-40
https://www.auscert.org.au/bulletins/ESB-2023.3907
https://cxsecurity.com/cveshow/CVE-2023-29300/
Solutions
Refer to the announcement or patch by the vendor: https://helpx.adobe.com/security/products/coldfusion/apsb23-40.html