vulnerability

APSB17-14: Security updates available for ColdFusion (CVE-2017-3066)

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Apr 27, 2017
Added
Jun 21, 2019
Modified
Mar 27, 2026

Description

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

Solutions

adobe-coldfusion-10-update-23adobe-coldfusion-11-update-12adobe-coldfusion-2016-release-update-4
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.