PT-2025-50290 · Adobe · Coldfusion

Published

2025-12-09

·

Updated

2025-12-10

·

CVE-2025-64897

CVSS v3.1

5.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier
Description An Improper Access Control issue exists in ColdFusion. An attacker with low privileges may be able to bypass security measures and gain limited unauthorized write access, potentially leading to a denial of service. User interaction is required for exploitation.
Recommendations Update ColdFusion to a version later than 2021.22. Update ColdFusion to a version later than 2023.16. Update ColdFusion to a version later than 2025.4.

Fix

DoS

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-15505
CVE-2025-64897

Affected Products

Coldfusion