NVD disclosure day

Published threat advisories for January 9, 2013

CVE advisoryKnown Exploit

CVE-2013-0631

Adobe ColdFusion Information Disclosure Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Adobe ColdFusion allows attackers to access sensitive information, posing a risk to business data. The exploitation of this flaw can lead to unauthorized data access and compromise. Organizations using affected versions face a significant business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2013-0629

Adobe ColdFusion Directory Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Adobe ColdFusion instances with unconfigured passwords allow unauthorized access to restricted directories. This could lead to data exposure and impact organizational systems. The risk involves potential unauthorized data access and system compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2013-0625

Adobe ColdFusion Authentication Bypass Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Affected organizations face a risk of unauthorized access and potential code execution due to an authentication bypass vulnerability in Adobe ColdFusion. Attackers can exploit this flaw when passwords are not configured, leading to a compromise of business systems and data.

• CISA KEV