Impact
ColdFusion is affected by an Improper Access Control vulnerability that allows an attacker to read files and directories outside the intended access scope. This flaw can lead to sensitive data exposure through arbitrary file system reads with no user interaction required. The weakness is due to insufficient validation of file paths accessed by the application, as indicated by the CWE‑284 classification.
Affected Systems
Advisory reports that Adobe ColdFusion versions 2023 and 2025 are vulnerable. No specific version ranges are provided, so all installations of these product lines should be considered at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity for this issue. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no publicly known active exploitation at the time of this analysis. Based on the description, it is inferred that the lack of user interaction requirement allows remote exploitation, most likely over the web by sending crafted requests to the affected application.
OpenCVE Enrichment