ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
History

Tue, 09 Dec 2025 23:45:00 +0000

Type Values Removed Values Added
Description ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
Title ColdFusion | Insufficiently Protected Credentials (CWE-522)
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: adobe

Published: 2025-12-09T23:41:10.587Z

Updated: 2025-12-10T04:57:41.539Z

Reserved: 2025-11-11T22:48:38.847Z

Link: CVE-2025-64898

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-12-10T00:16:10.937

Modified: 2025-12-10T00:16:10.937

Link: CVE-2025-64898

cve-icon Redhat

No data.