Adobe ColdFusion Insufficiently Protected Credentials Vulnerability Allowing Unauthorized Write Access

Vulnerability

A vulnerability exists in Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier, due to insufficient protection of credentials. This vulnerability could lead to limited unauthorized write access. An attacker might exploit this issue to gain unauthorized access by taking advantage of credentials that are improperly stored or transmitted. Notably, exploitation of this vulnerability does not require user interaction.

Impact

Exploitation of this vulnerability could result in unauthorized write access, potentially allowing attackers to manipulate files or data on the affected system.

Remediation

Users are advised to update to ColdFusion 2025 Update 5, ColdFusion 2023 Update 17, or ColdFusion 2021 Update 23. For more information on these updates, refer to the Adobe ColdFusion Security Bulletin APSB25-105.

Added: Dec 10, 2025, 12:46 AM
Updated: Dec 10, 2025, 12:46 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
5.0
exploitability
7.6
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.