ZeroHour

CVE-2013-0631

KEVmoderate

Information Disclosure Flaw in Adobe ColdFusion Listed as Actively Exploited

CISA: Adobe ColdFusion Information Disclosure Vulnerability

CVSS
EPSS
66%p99
Published
KEV added
AI analysis

Adobe ColdFusion contains an information disclosure vulnerability (CWE-200) that can result in sensitive information being exposed from a compromised server. The available data does not detail the exact trigger or access vector, but the flaw affects ColdFusion server deployments and leads to disclosure of information once a server is compromised. An attacker who successfully exploits it gains access to potentially sensitive data residing on the affected ColdFusion server. Any organization running Adobe ColdFusion may be affected; the data does not specify affected version ranges. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, carries a 65.9% EPSS probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

What to do: Apply Adobe's security updates for your installed ColdFusion version per vendor instructions, which is CISA's required action; given the 99th-percentile EPSS score and KEV listing, prioritize patching immediately. Inventory all ColdFusion servers (version is visible in the ColdFusion Administrator), reduce their network exposure, and review server logs for indicators of information disclosure or compromise. Ransomware use is reported as unknown, so treat any signs of exploitation as a possible precursor to broader compromise.

Affected
Adobe ColdFusion
Estimated exposure
moderateon the order of 10,000-50,000 internet-exposed ColdFusion servers (total deployments, including internal ones, likely higher) — Public internet scans have historically shown tens of thousands of Adobe ColdFusion instances exposed to the internet, and typical enterprise deployment patterns imply additional internal servers, so plausibly affected deployments are at…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
ColdFusion
Weakness
CWE-200

In the news