Number: AV17-058
Date: 27 April 2017
Purpose
The purpose of this advisory is to bring attention to a recently released security update for Adobe ColdFusion.
Assessment
Adobe has released Security Bulletin APSB17-14 to address critical vulnerabilities that could potentially be exploited using cross-site scripting and java deserialization.
Affected software versions:
- ColdFusion (2016 release) Update 3 and earlier versions
- ColdFusion 11 Update 11 and earlier versions
- ColdFusion 10 Update 22 and earlier versions
CVE References: CVE-2017-3008 and CVE-2017-3066.
Suggested action
CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.
References
APSB17-14: https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html