CVE-2013-0631
Published · Updated
63Vexday Risk Score
Prioritize patching. It under exploitation confirmed by CISA.
ssvc Actcvss 7.5epss 66%
from disclosure to weapon
Published on NVDJan 9
CISA KEV+3344d
exploitation probability
66%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-09-07
Apply updates per vendor instructions.
In short
Adobe ColdFusion versions 9.0 through 9.0.2 have a vulnerability that allows attackers to access sensitive information through unspecified methods. This flaw was actively exploited by malicious actors in January 2013.
Technical detail
An information disclosure vulnerability exists in ColdFusion 9.0-9.0.2 that permits unauthorized access to sensitive data via unspecified attack vectors. The vulnerability was confirmed through active exploitation in the wild, indicating practical exploitability without requiring special privileges or user interaction.
Summary generated and translated by AI from the official description.
The full analysis of this CVE is available in Portuguese →
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a