Логотип exploitDog
bind:CVE-2025-49546
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-49546

Количество 3

Количество 3

nvd логотип

CVE-2025-49546

7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS3: 2.4
EPSS: Низкий
github логотип

GHSA-pf9f-7gg3-qgq3

7 месяцев назад

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability to disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS3: 2.4
EPSS: Низкий
fstec логотип

BDU:2025-08386

7 месяцев назад

Уязвимость программной платформы ColdFusion, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 2.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-49546

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to a partial application denial-of-service. A high-privileged attacker could exploit this vulnerability to partially disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS3: 2.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-pf9f-7gg3-qgq3

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Access Control vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability to disrupt the availability of the application. Exploitation of this issue does not require user interaction and scope is unchanged. The vulnerable component is restricted to internal IP addresses.

CVSS3: 2.4
0%
Низкий
7 месяцев назад
fstec логотип
BDU:2025-08386

Уязвимость программной платформы ColdFusion, связанная с недостаточной проверкой поступающих запросов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 2.7
0%
Низкий
7 месяцев назад

Уязвимостей на страницу