Junglewise Threat Intelligence

CVE-2013-0632: Adobe ColdFusion Authentication Bypass Vulnerability

CVE-2013-0632 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-03

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

An authentication bypass vulnerability in Adobe ColdFusion's administrator.cfc allows remote attackers to gain administrative access. Attackers can log in to the RDS component using a default empty password and leverage that session to access the administrative web interface, potentially leading to arbitrary code execution.

Affected products

  • Adobe ColdFusion 9.0, 9.0.1, 9.0.2, 10

Timeline

  • 2013-01-16: disclosed: NVD Published Date
  • 2013-01-17: other: Initial CVE Analysis
  • 2013-01-01: exploited: Exploited in the wild in January 2013
  • 2022-03-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats