Junglewise Threat Intelligence

CVE-2013-0625: Adobe ColdFusion Authentication Bypass Vulnerability

CVE-2013-0625 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-07

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion 9.0 through 9.0.2 contains an authentication bypass vulnerability when a password is not configured. Remote attackers can exploit this to bypass authentication and potentially execute arbitrary code.

Affected products

  • Adobe ColdFusion 9.0, 9.0.1, 9.0.2

Timeline

  • 2013-01-08: disclosed: NVD Published Date
  • 2013-01-01: exploited: Exploited in the wild in January 2013
  • 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats