Description
Due to the insecure WDDX deserialization vulnerability, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Security updates available for Adobe ColdFusion | APSB23-52
Technical Advisory: Adobe ColdFusion WDDX Deserialization Gadgets