CVE-2023-38203 Details
Description
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
A deserialization of untrusted data vulnerability has been identified in Adobe ColdFusion versions 2018u17 and earlier, 2021u7 and earlier, and 2023u1 and earlier. This vulnerability could allow for arbitrary code execution, and its exploitation does not require user interaction.
Users are advised to update to ColdFusion 2018 Update 18, ColdFusion 2021 Update 8, or ColdFusion 2023 Update 2. For JEE installations, set the JVM flag to denylist certain packages vulnerable to deserialization issues. Consult the ColdFusion support matrix for JDK version requirements and apply the latest update release.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 8, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38203 | CISA-ADP | Third Party AdvisoryUS Government Resource |
| https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html | CVE | PatchVendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html | [email protected] | PatchVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Adobe ColdFusion Deserialization of Untrusted Data Vulnerability | Jan 8, 2024 | Jan 29, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe coldfusion | 2018 - 2018 update1 2018 update10 2018 update11 2018 update12 2018 update13 2018 update14 2018 update15 2018 update16 2018 update17 2018 update2 2018 update3 2018 update4 2018 update5 2018 update6 2018 update7 2018 update8 2018 update9 2021 - 2021 update1 2021 update2 2021 update3 2021 update4 2021 update5 2021 update6 2021 update7 2023 - 2023 update1 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Jan 23, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 9, 2024 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Jul 20, 2023 | Initial Analysis | [email protected] |