#VU51623 Input validation error in ColdFusion - CVE-2021-21087
Published: March 22, 2021
ColdFusion
Adobe
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote non-authenticated attacker can send specially crafted data to the application and execute arbitrary code on the system.
Remediation
Install updates from vendor's website.
NOTE, Adobe recommends updating your ColdFusion JDK/JRE to the latest version of the LTS releases for 1.8 and JDK 11. Applying the ColdFusion update without a corresponding JDK update will NOT secure the server.
Please, see the vendor's advisory for details.