CVE-2013-0629

adobe coldfusion

Published 9 Jan 2013 · updated 16 Jun 2026 · Analyzed

7.5 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 7 Mar 2022, with a remediation deadline of 7 Sept 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

References