Adobe ColdFusion Server Administration Console Detected

medium Web Application Scanning Plugin ID 113068

Synopsis

Adobe ColdFusion Server Administration Console Detected

Description

Adobe ColdFusion server administration console has been detected on the target web application. This may present an attacker with an exploit vector which could be leveraged using other techniques, such as a Brute-Force or Dictionary Attack, allowing an attacker to gain access to administrative functionality.

Solution

Restrict or disable access to the Adobe ColdFusion administration console.

See Also

https://helpx.adobe.com/coldfusion/configuring-administering/administering-coldfusion-security.html

Plugin Details

Severity: Medium

ID: 113068

Type: remote

Published: 12/1/2021

Updated: 12/1/2021

Scan Template: api, scan, pci

Risk Information

CVSS v2

Risk Factor: Low

Base Score: 2.6

Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

Reference Information