S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-29298 Scanner

Detects 'Improper Access Control' vulnerability in Adobe ColdFusion affects v. 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.5k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-29298
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
ColdFusionby Adobe
0
Updated Aug 22, 2026View on NVD →
Detail

Adobe ColdFusion is a popular application server used for developing web applications in Java, .NET, and other programming languages. The product is widely used to develop dynamic web pages, applications and services. It is essential for organizations of all sizes, especially for ones that require the flexibility and scalability of a multi-tier infrastructure.

The CVE-2023-29298 vulnerability detected in Adobe ColdFusion versions 2018u16 and earlier, 2021u6 and earlier and 2023.0.0.330468 and earlier is an Improper Access Control vulnerability. This vulnerability could lead to security feature bypass and allow attackers to access the administration CFM and CFC endpoints. This issue could be exploited by hackers without any user interaction.

When exploited, this vulnerability can lead to a security breach in any organization's digital assets. Attackers can gain unauthorized access to critical data, sensitive information, and system resources. They can make changes to the application's source code, manipulate data, or launch attacks against other systems on the network. The impact of such attacks could be devastating to businesses, causing financial losses, reputational damage, and legal consequences.

In conclusion, it is essential for businesses to stay informed of the potential vulnerabilities in their digital assets. Through the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities that could pose a threat to their systems. This platform's advanced security testing and reporting capabilities enable users to identify vulnerabilities promptly, take appropriate measures, and protect their businesses from cyber-attacks. By being proactive in their security strategy, businesses can safeguard their digital assets and maintain public trust.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Adobe ColdFusion users should take the following precautionary measures:

  • Update to the latest version of Adobe ColdFusion;
  • Install security patches as soon as they become available;
  • Implement Access Control Lists (ACLs) to limit access to administration CFM and CFC endpoints;
  • Monitor system logs and network traffic for any signs of suspicious activity;
  • Employ a comprehensive security solution that includes firewalls, intrusion detection and prevention systems, and anti-virus software.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.