Adobe ColdFusion
cpe:2.3:a:adobe:coldfusion:*:*:*:*:*:*:*
- <= 2025.3
- <= 2023.15
- <= 2021.21
A path traversal vulnerability has been identified in Adobe ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier. This vulnerability allows attackers to execute arbitrary code by improperly limiting pathnames to restricted directories.
Exploitation of this vulnerability could lead to arbitrary code execution on the server.
Users are advised to update to ColdFusion 2025 Update 4, ColdFusion 2023 Update 16, or ColdFusion 2021 Update 22. For instructions on how to update, refer to the Adobe ColdFusion downloads page. Additionally, for ColdFusion 2025, 2023, and 2021, set the JVM flag '-Djdk.serialFilter' to exclude certain packages, in the appropriate startup file for the application server being used.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.