Description
Due to the insecure WDDX deserialization vulnerability, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Security updates available for Adobe ColdFusion | APSB23-52
Technical Advisory: Adobe ColdFusion WDDX Deserialization Gadgets
Related Vulnerabilities
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-5487)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-3273)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2013-5000)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2019-14888)
IBM WebSEAL Missing Authorization Vulnerability (CVE-2019-4158)