Description
Due to the insecure WDDX deserialization vulnerability, an unauthenticated attacker might send a specially-crafted serialized request to execute arbitrary code on the system.
Remediation
Upgrade to the latest version of Adobe ColdFusion
References
Security updates available for Adobe ColdFusion | APSB23-52
Technical Advisory: Adobe ColdFusion WDDX Deserialization Gadgets
Related Vulnerabilities
Oracle JRE CVE-2014-2409 Vulnerability (CVE-2014-2409)
Serendipity Other Vulnerability (CVE-2005-1451)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1830)
Oracle JRE CVE-2019-2945 Vulnerability (CVE-2019-2945)
Moodle Improper Privilege Management Vulnerability (CVE-2019-3849)