CVE Vulnerabilities

CVE-2013-0625

Improper Authentication

Published: Jan 09, 2013 | Modified: Oct 22, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ColdfusionAdobe9.0 (including)9.0 (including)
ColdfusionAdobe9.0.1 (including)9.0.1 (including)
ColdfusionAdobe9.0.2 (including)9.0.2 (including)

Potential Mitigations

References