CVE-2025-64898: ColdFusion | Insufficiently Protected Credentials (CWE-522)
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could result in limited unauthorized write access. An attacker could leverage this vulnerability to gain unauthorized access by exploiting improperly stored or transmitted credentials. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64898?
CVE-2025-64898 is considered a medium severity vulnerability due to the potential for unauthorized write access.
How do I fix CVE-2025-64898?
To fix CVE-2025-64898, you should update to the latest version of Adobe ColdFusion that is not affected by this vulnerability.
What versions of ColdFusion are affected by CVE-2025-64898?
CVE-2025-64898 affects ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier.
What consequences can arise from CVE-2025-64898?
Exploiting CVE-2025-64898 could allow attackers to gain unauthorized access and manipulate data without proper permissions.
How can I detect if my system is vulnerable to CVE-2025-64898?
You can determine if your system is vulnerable to CVE-2025-64898 by checking the current version of Adobe ColdFusion running on your server.