CVE-2025-43559: ColdFusion | Improper Input Validation (CWE-20)
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43559?
CVE-2025-43559 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2025-43559?
To fix CVE-2025-43559, you should update Adobe ColdFusion to the latest version recommended by Adobe.
Which versions of ColdFusion are affected by CVE-2025-43559?
CVE-2025-43559 affects ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier.
What kind of attacks can exploit CVE-2025-43559?
CVE-2025-43559 can be exploited by attackers to execute arbitrary code within the context of the current user.
Is it necessary to implement additional security measures with CVE-2025-43559?
Yes, additional security measures should be considered alongside updating ColdFusion to mitigate risks from CVE-2025-43559.