CVE-2023-26347 in https://████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true
High
U
U.S. Dept Of Defense
Submitted None
Actions:
Reported by
traveler5260
Vulnerability Details
Technical details and impact analysis
**Description:**
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints.
## References
https://nvd.nist.gov/vuln/detail/CVE-2023-26347
https://vuldb.com/?id.245747
## Impact
An attacker, without authentication, could exploit this vulnerability to gain access to the administration CFM and CFC endpoints.
## System Host(s)
██████████.mil
## Affected Product(s) and Version(s)
https://█████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true
## CVE Numbers
CVE-2023-26347
## Steps to Reproduce
Access to the https://████████.mil/hax/..CFIDE/adminapi/administrator.cfc?method=getBuildNumber&_cfclient=true site.
## Suggested Mitigation/Remediation Actions
Check the [Release Note](https://helpx.adobe.com/security/products/coldfusion/apsb23-52.html) and upgrade the version of Adobe ColdFusion product
Related CVEs
Associated Common Vulnerabilities and Exposures
CVE-2023-26347
HIGH
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An unauthenticated attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic