Junglewise Threat Intelligence

CVE-2025-64898: Adobe ColdFusion insufficiently protected credentials

CVE-2025-64898 · Severity: medium · CVSS 5.3 · Published 2025-12-10

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion, a platform for building and deploying web applications, is affected by a security flaw in how it handles user credentials. An attacker could exploit this to gain unauthorized write access to the system, potentially allowing them to modify data or configuration settings. This issue does not require any interaction from a legitimate user to be exploited.

Technical details

Adobe ColdFusion is vulnerable to an 'Insufficiently Protected Credentials' flaw (CWE-522). The vulnerability stems from credentials being improperly stored or transmitted, which can be intercepted or recovered by an attacker. This is a network-based attack that requires no prior authentication or user interaction. Successful exploitation allows for limited unauthorized write access to the affected system. Adobe has addressed this in security bulletin APSB25-105, and users are advised to update to the latest patched versions.

Affected products

  • Adobe ColdFusion 2025.4, 2023.16, 2021.22 and earlier

Timeline

  • 2025-12-10: disclosed
  • 2025-12-10: advisory: Adobe security bulletin APSB25-105 published

References

Related threats