ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Dec 2025 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction. | |
| Title | ColdFusion | Insufficiently Protected Credentials (CWE-522) | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published: 2025-12-09T23:41:10.587Z
Updated: 2025-12-10T04:57:41.539Z
Reserved: 2025-11-11T22:48:38.847Z
Link: CVE-2025-64898
No data.
Status : Received
Published: 2025-12-10T00:16:10.937
Modified: 2025-12-10T00:16:10.937
Link: CVE-2025-64898
No data.