Impact
ColdFusion suffers from a use of a broken or risky cryptographic algorithm, classified as CWE-327, that can allow an attacker to read sensitive memory contents. The disclosed information could reveal confidential data, compromising the integrity and confidentiality of the system without user interaction.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. No specific version numbers are supplied beyond the product names, but any deployment of these editions may contain the issue.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity while the EPSS score of less than 1% points to low current exploitation probability. The flaw is not listed in the CISA KEV catalog. Exploitation does not require user interaction and is likely to be conducted remotely through network channels that the ColdFusion application processes. No additional prerequisites are specified beyond the cryptographic configuration used by the application.
OpenCVE Enrichment