Security Scan Missing ColdFusion Updates
Our team has some security compliance policies with some scans for our new ColdFusion server. The scan is reporting this:
The version of Adobe ColdFusion installed on the remote Windows host is prior to 2018.x Update 16 or 2021.x Update 6.
It is, therefore, affected by multiple vulnerabilities as referenced in the APSB23-25 advisory.
Update directory : E:\cfusion\lib\updates
Missing cumulative hotfix : chf2021000006.jar
Also note that to be fully protected the Java JDK must be patched along with applying the vendor patch.
We are currently running update 16, and I see the following in the admin portal under Sytem Information:
Server Details
Server Product ColdFusion (2021 Release)
Version 2021.0.16.330307
Tomcat Version 9.0.93.0
Edition Standard
Operating System Windows Server 2022
OS Version 10.0
Update Level E:/cfusion/lib/updates/chf20210016.jar
Adobe Driver Version 5.1.4 (Build 0001)
JVM Details
Java Version 11.0.24
Java Vendor Oracle Corporation
Java Vendor URL https://openjdk.java.net/
In the directory E:/cfusion/lib/updates/, I have all of the corresonding chf20210016.jar for each update. Does anyone know how I can get the scan to come back clean for our compliance?
