Impact
The reported flaw in ColdFusion is an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability. This weakness allows an attacker to reference files and directories outside the intended storage area, enabling an attacker to exploit resources under which the ColdFusion application is running. Because the vulnerability can fully compromise the availability, confidentiality and integrity of the affected system. This flaw is classified as CWE‑22.
Affected Systems
Adobe ColdFusion 2023 and ColdFusion 2025 are identified as affected by the CNA. Specific version numbers are not listed, so all current releases of those product lines should be considered vulnerable until an advisory confirms otherwise.
Risk and Exploitability
The CVSS base score of 9.1 reflects the severity of arbitrary code execution. The EPSS score of 32% indicates that the likelihood of exploitation in the wild is moderately high, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote HTTP request to the ColdFusion server; this inference is drawn from the fact that no user interaction is required. Once path traversal succeeds, the attacker can change the effective execution scope, potentially affecting the entire system running the ColdFusion service.
OpenCVE Enrichment