Adobe security update

Number: AV17-058
Date: 27 April 2017

Purpose

The purpose of this advisory is to bring attention to a recently released security update for Adobe ColdFusion.

Assessment

Adobe has released Security Bulletin APSB17-14 to address critical vulnerabilities that could potentially be exploited using cross-site scripting and java deserialization. 

Affected software versions:

  • ColdFusion (2016 release) Update 3 and earlier versions 
  • ColdFusion 11 Update 11 and earlier versions
  • ColdFusion 10 Update 22 and earlier versions

CVE References: CVE-2017-3008 and CVE-2017-3066.

Suggested action

CCIRC recommends that system administrators test and deploy the vendor-released updates to affected applications accordingly.

References

APSB17-14: https://helpx.adobe.com/security/products/coldfusion/apsb17-14.html

Date modified: