CVE-2025-49546

Severity
2.4LOW
EPSS
0.0%
top 85.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8

Description

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:LExploitability: 0.9 | Impact: 1.4

Affected Packages2 packages

CVEListV5adobe/coldfusion2021.20
NVDadobe/coldfusion2021, 2023, 2025+2

🔴Vulnerability Details

2
CVEList
ColdFusion | Improper Access Control (CWE-284)2025-07-08
GHSA
GHSA-pf9f-7gg3-qgq3: ColdFusion versions 20252025-07-08
CVE-2025-49546 (LOW CVSS 2.4) | ColdFusion versions 2025.2 | cvebase.io