ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
References
| Link | Resource |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb25-105.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-10 00:16
Updated : 2025-12-12 18:40
NVD link : CVE-2025-64898
Mitre link : CVE-2025-64898
CVE.ORG link : CVE-2025-64898
JSON object : View
Products Affected
adobe
- coldfusion
CWE
CWE-522
Insufficiently Protected Credentials
