CVE-2013-0631highunder attack

CVE-2013-0631

Published · Updated

63Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.5epss 66%
from disclosure to weapon
Published on NVDJan 9
CISA KEV+3344d
exploitation probability
66%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-09-07

Apply updates per vendor instructions.

In short

Adobe ColdFusion versions 9.0 through 9.0.2 have a vulnerability that allows attackers to access sensitive information through unspecified methods. This flaw was actively exploited by malicious actors in January 2013.

Technical detail

An information disclosure vulnerability exists in ColdFusion 9.0-9.0.2 that permits unauthorized access to sensitive data via unspecified attack vectors. The vulnerability was confirmed through active exploitation in the wild, indicating practical exploitability without requiring special privileges or user interaction.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
n/a · n/a