CVE DATABASE / CVE-2010-2861
CVE-2010-2861
Adobe ColdFusion Directory Traversal Vulnerability
Confirmed exploited in the wild. Added 2022-03-25.
Federal remediation due 2022-04-15.
Required action: Apply updates per vendor instructions.
Summary
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
CVSS 3.1 breakdown
| Base score | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Attack vector | NETWORK |
| Attack complexity | LOW |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | HIGH |
| Integrity | HIGH |
| Availability | HIGH |
Weakness type (CWE)
Affected products
Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.
References
- http://securityreason.com/securityalert/8137
- http://securityreason.com/securityalert/8148
- http://www.adobe.com/support/security/bulletins/apsb10-18.html
- http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/
- http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-2861
Data: NIST NVD + CISA KEV. NVD last modified 2026-04-21. Always verify against the vendor advisory before acting.