Incorrect Authorization Vulnerability in Adobe ColdFusion
CVE-2025-43565

8.4HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
13 May 2025

What is CVE-2025-43565?

Adobe ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are impacted by an Incorrect Authorization vulnerability. This flaw allows a high-privileged attacker to execute arbitrary code within the context of the current user, effectively bypassing existing security controls. Successful exploitation requires user interaction, indicating a need for caution among users of affected versions.

Affected Version(s)

ColdFusion 0 <= 2021.19

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-43565 : Incorrect Authorization Vulnerability in Adobe ColdFusion