Adobe ColdFusion Path Traversal Vulnerability
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
CISA entryAdobe · AUTOMATIC DISCOVERY
Adobe ColdFusion is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
This record passed BlackTree's automatic primary-source checks with a confidence score of 82. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.
This discovery does not establish a product-specific support or retirement date. A missing date does not mean support continues.
Adobe ColdFusion is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.
Used to provide application, infrastructure or operational services to other systems and users.
Deployed on servers, virtual machines, containers or managed infrastructure.
This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .
| Product | Adobe ColdFusion |
|---|---|
| Release | Lifecycle policy |
| Start or release | Not extracted |
| Lifecycle boundary | Continuous or not dated in the source |
| Date precision | Unknown |
These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.
Adobe ColdFusion contains a path traversal vulnerability that could lead to arbitrary code execution in the context of the current user.
CISA entryAdobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CISA entryAdobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CISA entryAdobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CISA entryAdobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CISA entryAdobe ColdFusion contains a deserialization of untrusted data vulnerability that could result in code execution in the context of the current user.
CISA entryShowing the 6 most recently added of 16 product-family matches.
OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.
No package advisories have been linked for this product identity.
This is not evidence that the product has no vulnerabilities.
Work with your Adobe account representative for details regarding the annual support fee. Ongoing Maintenance and Support is also available to you under the following conditions: | Renewals . When renewing Maintenance and Support for any Commercial Adobe Software products listed on Adobe's product list, provided that version of software has not been end-of-lifed, the Annual Support Fee shall be, (i) for the Initial Term, the Annual Support Fee established during the initial purchase, (ii) for the first renewal term, if so renewed, the Annual Support Fee established by the initial purchase increased by three percent (3%), (iii) for the second through the fourth renewal terms, if so renewed, the Annual Support Fee for immediately preceding renewal term increased by three percent (3%), (iv) and for the fifth and subsequent renewal term(s), the lesser of 20% of the then-current List Price for the software or the Annual Support Fee for the immediately preceding renewal term increased by the applicable Consumer Price Index (CPI)*, for the 12-month period preceding the renewal date. | Extended support. If the version of a Program licensed by Customer will reach End of Life as defined in Section 1 e) above, Customer may elect to purchase Extended Support for a maximum period of another two (2) years from the End of Life Date, provided that Extended Support is available for that version of the Program. Information about Programs that have been or soon will reach End of Life and Extended Support availability dates by product version are published on Adobe's website at www.adobe.com/support. If Customer elects to purchase Extended Support, the Annual Support Fee for the first year and or the renewal (second year), shall be an additional 25% of the Annual Support fee for the current renewal term. | If extended support is renewed, the renewal fee would be the Annual Support Fee paid for the prior year increased by the applicable Consumer Price Index (CPI)*, for the 12-month period preceding the renewal date. Should Customer upgrade to the next major version of the Software (for example, upgrade from 4.0 to 5.0), the Annual Support Fee for the upgraded version shall be the lesser of twenty percent (20%) of the then-current list price of the license fee for such upgraded version, or the Annual Support Fee for the last renewal before renewing under Extended Support increased by the applicable Consumer Price Index (CPI)*, for the 12-month period preceding the renewal date. | * for the USA and Mexico, CPI is as published by the United States Department of Labor, Bureau of Labor Statistics. For Canada, CPI is as published by the Bank of Canada
Official vendor lifecycle or product-change property. Extracted records require human review.
Open official vendor source