Executive brief
Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw in how it handles user credentials. An attacker could exploit this to gain unauthorized write access to the system, potentially allowing them to modify data or configuration settings. This issue does not require any interaction from a legitimate user to be exploited.
Technical details
Adobe ColdFusion is vulnerable to an 'Insufficiently Protected Credentials' flaw (CWE-522). The vulnerability stems from credentials being improperly stored or transmitted, which can be intercepted or recovered by an attacker. This is a network-based attack that requires no prior authentication or user interaction. Successful exploitation allows for limited unauthorized write access to the affected system. Adobe has addressed this in security bulletin APSB25-105, and users are advised to update to the latest patched versions.
Affected products
- Adobe ColdFusion 2025.4, 2023.16, 2021.22 and earlier
Timeline
- 2025-12-10: disclosed
- 2025-12-10: advisory: Adobe security bulletin APSB25-105 published