CVE-2025-64897: ColdFusion | Improper Access Control (CWE-284)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability. A low privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized write access potentially resulting in denial of service. Exploitation of this issue requires user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64897?
CVE-2025-64897 is classified as a low severity vulnerability impacting Adobe ColdFusion.
How do I fix CVE-2025-64897?
To fix CVE-2025-64897, you should update Adobe ColdFusion to the latest version as per the vendor's recommendations.
What versions of ColdFusion are affected by CVE-2025-64897?
CVE-2025-64897 affects Adobe ColdFusion versions 2025.4, 2023.16, and 2021.22 and earlier.
What is the nature of the vulnerability in CVE-2025-64897?
CVE-2025-64897 is an Improper Access Control vulnerability that allows a low privileged attacker to gain unauthorized write access.
What can be the impact of CVE-2025-64897?
The impact of CVE-2025-64897 may include denial of service due to unauthorized write access to the affected system.