First published: Tue May 13 2025(Updated: )
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | <2025.1 | |
Adobe ColdFusion | <2023.13 | |
Adobe ColdFusion | <2021.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43564 is considered a significant vulnerability due to its potential for arbitrary file system read, affecting sensitive data security.
To address CVE-2025-43564, it is recommended to update Adobe ColdFusion to the latest version that includes security patches.
CVE-2025-43564 affects Adobe ColdFusion versions 2025.1, 2023.13, 2021.19, and earlier.
Exploitation of CVE-2025-43564 could allow attackers to access or modify sensitive data without proper authorization.
Currently, the best approach to mitigate CVE-2025-43564 is to apply the latest updates and security patches provided by Adobe.