CVE-2025-43564: ColdFusion | Incorrect Authorization (CWE-863)
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43564?
CVE-2025-43564 is considered a significant vulnerability due to its potential for arbitrary file system read, affecting sensitive data security.
How do I fix CVE-2025-43564?
To address CVE-2025-43564, it is recommended to update Adobe ColdFusion to the latest version that includes security patches.
What versions of ColdFusion are affected by CVE-2025-43564?
CVE-2025-43564 affects Adobe ColdFusion versions 2025.1, 2023.13, 2021.19, and earlier.
What types of attacks can CVE-2025-43564 facilitate?
Exploitation of CVE-2025-43564 could allow attackers to access or modify sensitive data without proper authorization.
Is there a workaround for CVE-2025-43564?
Currently, the best approach to mitigate CVE-2025-43564 is to apply the latest updates and security patches provided by Adobe.