RULE(RULE ID:712728)

Rule General Information
Release Date: 2018-07-02
Rule Name: WEB-SERVER Adobe ColdFusion DataServicesCFProxy ROME Framework Insecure Deserialization Vulnerability (CVE-2018-4939)
Severity:
CVE ID:
Rule Protection Details
Description: Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux
Reference: SecurityFocusBID:103718
AdobeSecurityBulletins:apsb18-14
Solutions
Adobe has issued a fix on the official website. For more advisory, please visit:
https://helpx.adobe.com/security/products/coldfusion/apsb18-14.html