VORANT. Threat Intelligence Sign in Get the full feed

Adobe ColdFusion path traversal flaw disclosed

high vulnerability technology

A path traversal vulnerability in Adobe ColdFusion (CVE-2024-53961) could let unauthenticated attackers read arbitrary system files, with PoC code confirmed.

The Japan Computer Emergency Response Team/IPA has issued an alert regarding a path traversal vulnerability in Adobe ColdFusion, tracked as CVE-2024-53961. The flaw allows an unauthenticated remote attacker to view arbitrary system files on affected servers, potentially exposing sensitive configuration or data files.

Adobe has confirmed the existence of proof-of-concept (PoC) exploit code for this vulnerability, raising concern that exploitation attempts may increase. IPA is urging organizations running Adobe ColdFusion to apply the vendor-provided updates as soon as possible, following Adobe's official upgrade guidance to mitigate the risk of file disclosure attacks.

Mentioned in this report

Vulnerabilities CVE-2024-53961

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241224.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free