By deploying any Hillstone Networks solution with the IPS function, the Adobe ColdFusion Deserialization vulnerability can be quickly detected and effectively intercepted, preventing the server from being attacked. Hillstone Networks has added signatures to the IPS signature database version 2.1.245. If the user does not need it, you can prevent external network traffic from accessing port 1099 to prevent it from being exploited by hackers. Update the bug fix release provided by Adobe to eliminate the damage caused by the vulnerability. Adobe Systems ColdFusion 11 Update 13 and prior.Adobe Systems ColdFusion (2016 release) Update 5 and prior.If the vulnerability is exploited, arbitrary code execution in the context of the target system can be implemented. An unauthenticated attacker could exploit this vulnerability by sending elaborate malicious serialization parameters to the target application via RMI calls. Recently, Adobe fixed a deserialization vulnerability in AdobeCloudFusion Flex integration service.ĬVE-2018-4939: This vulnerability is caused by a lack of input validation for RMI method parameters in the DataServicesCFProxy class. The Flex integration service includes ColdFusion, which allows Flash applications to communicate with the ColdFusion server via Java RMI. Adobe ColdFusion is an application development platform.
0 Comments
Leave a Reply. |