# Adobe ColdFusion path traversal flaw disclosed

Published: 2024-12-23 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/1e94dedf-c2fb-50e4-82b0-b9ade7a525a6/adobe-coldfusion-path-traversal-flaw-disclosed

> A path traversal vulnerability in Adobe ColdFusion (CVE-2024-53961) could let unauthenticated attackers read arbitrary system files, with PoC code confirmed.

The Japan Computer Emergency Response Team/IPA has issued an alert regarding a path traversal vulnerability in Adobe ColdFusion, tracked as CVE-2024-53961. The flaw allows an unauthenticated remote attacker to view arbitrary system files on affected servers, potentially exposing sensitive configuration or data files.

Adobe has confirmed the existence of proof-of-concept (PoC) exploit code for this vulnerability, raising concern that exploitation attempts may increase. IPA is urging organizations running Adobe ColdFusion to apply the vendor-provided updates as soon as possible, following Adobe's official upgrade guidance to mitigate the risk of file disclosure attacks.

## Mentioned in this report

- Vulnerabilities: CVE-2024-53961

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20241224.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1e94dedf-c2fb-50e4-82b0-b9ade7a525a6/adobe-coldfusion-path-traversal-flaw-disclosed.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
