ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | epss 
 | epss 
 | 
Tue, 24 Jun 2025 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction. | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed. | 
Wed, 28 May 2025 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Adobe Adobe coldfusion | |
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update10:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update11:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update12:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update13:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update14:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update15:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update16:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update17:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update18:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update5:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update6:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update7:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update8:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2021:update9:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:-:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update10:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update11:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update12:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update1:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update2:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update3:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update4:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update5:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update6:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update7:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update8:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2023:update9:*:*:*:*:*:* cpe:2.3:a:adobe:coldfusion:2025:-:*:*:*:*:*:* | |
| Vendors & Products | Adobe Adobe coldfusion | 
Tue, 08 Apr 2025 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 08 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction. | |
| Title | ColdFusion | Improper Access Control (CWE-284) | |
| Weaknesses | CWE-284 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: adobe
Published: 2025-04-08T20:02:51.732Z
Updated: 2025-06-24T17:56:30.686Z
Reserved: 2025-03-20T17:36:17.300Z
Link: CVE-2025-30281
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-04-08T20:33:03.160Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-04-08T20:15:25.670
Modified: 2025-07-15T18:40:24.337
Link: CVE-2025-30281
 Redhat
                        Redhat
                    No data.