ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction.
Metrics
Affected Vendors & Products
References
History
Thu, 11 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe coldfusion |
|
| Vendors & Products |
Adobe
Adobe coldfusion |
Tue, 09 Dec 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction. | |
| Title | ColdFusion | Improper Access Control (CWE-284) | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2025-12-09T23:41:07.028Z
Updated: 2025-12-11T15:34:40.088Z
Reserved: 2025-11-11T22:48:38.847Z
Link: CVE-2025-64897
Updated: 2025-12-11T15:14:48.298Z
Status : Received
Published: 2025-12-10T00:16:10.767
Modified: 2025-12-10T00:16:10.767
Link: CVE-2025-64897
No data.