PT-2025-15651 · Adobe · Coldfusion
Published
2025-04-08
·
Updated
2025-06-24
·
CVE-2025-30281
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ColdFusion versions 2025.0 and earlier
ColdFusion versions 2023.12
ColdFusion versions 2021.18 and earlier
Description:
The issue is related to improper access control, which could allow a remote attacker to gain unauthorized access to protected information. This vulnerability may result in arbitrary file system read, enabling an attacker to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.
Recommendations:
For ColdFusion versions 2025.0 and earlier, update to a version that addresses the improper access control issue.
For ColdFusion versions 2023.12, apply the necessary security patches or updates to resolve the vulnerability.
For ColdFusion versions 2021.18 and earlier, consider restricting access to sensitive data and apply security updates as soon as they become available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coldfusion