Adobe ColdFusion Information Exposure Vulnerability Allowing Security Feature Bypass

Vulnerability

A vulnerability allowing information exposure has been identified in Adobe ColdFusion versions 2023.12, 2021.18, and 2025.0 and earlier. This vulnerability could lead to a bypass of security features. It allows a low-privileged attacker with local access to access sensitive information that could be used to further compromise the system or circumvent security mechanisms. Exploitation of this vulnerability does not require user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, potentially allowing for further system compromise or security feature bypass.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
3.1
exploitability
4.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.