Back

CRITICAL KEV Used in ransomware campaigns

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/

Published Aug 11, 2010 ·Due Apr 15, 2022

Description

Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (7)
  1. CISA ADP
    • SSVC technical impact changed from total to partial
    • CVSS severity changed from CRITICAL to HIGH
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H to CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    • CVSS score changed from 9.8 to 7.5
  2. CISA ADP
    • SSVC technical impact changed from partial to total
  3. CISA ADP
    • SSVC technical impact changed from total to partial
  4. CISA ADP
    • SSVC technical impact changed from partial to total
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Aug 11, 2010
Updated Oct 1, 2026
Reserved Jul 27, 2010
CISA Vulnrichment
Updated Aug 14, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity n/a
Public date n/a