Description
Due to the insecure WDDX deserialization vulnerability, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Related Vulnerabilities
Rukovoditel Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-30224)
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1633)
Apache HTTP Server Incorrect Authorization Vulnerability (CVE-2014-8109)
Atlassian Jira Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2021-26071)