CVE-2013-0631: Adobe ColdFusion Information Disclosure Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2022-03-07. EPSS: 66.4% chance of exploitation in the next 30 days.

Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.

Affected products

  • Adobe ColdFusion: version 9.0 only; version 9.0.1 only; version 9.0.2 only

Published 2013-01-09. Last modified 2026-06-16.