Adobe.ColdFusion.XmlTransform.Improper.Input.Validation

description-logoDescription

This indicates an attack attempt against an Information Disclosure vulnerability in Adobe ColdFusion.
The vulnerability is due to insufficient sanitizing when using the ColdFusion XmlTranform() function. A remote attacker can exploit this to gain unauthorized access to sensitive information.

affected-products-logoAffected Products

Adobe ColdFusion 2017.011.30161

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-01-18 22.478 Default_action:pass:drop
2022-10-11 22.411