Vulnerability record · CVE-2010-2861 · published 11 August 2010
CVE-2010-2861: Adobe ColdFusion administrator console path traversal file read
Adobe · Coldfusion
Adobe ColdFusion 9.0.1 and earlier contains directory traversal flaws in multiple administrator console pages, reachable through the locale parameter. An unauthenticated remote attacker can read arbitrary files from the server, which matters because ColdFusion configuration files often hold credentials and secrets.
Description
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable arbitrary file read with CVSS 9.8, KEV listing with known ransomware use, and near-maximum EPSS probability.
What it is
Adobe ColdFusion 9.0.1 and earlier contains directory traversal flaws in multiple administrator console pages, reachable through the locale parameter. An unauthenticated remote attacker can read arbitrary files from the server, which matters because ColdFusion configuration files often hold credentials and secrets.
Impact
An attacker gains read access to arbitrary files on the host, including ColdFusion configuration and credential material, enabling further compromise. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network via HTTP requests to CFIDE/administrator pages such as mappings.cfm, logging/settings.cfm, datasources/index.cfm, j2eepackaging/editarchive.cfm and enter.cfm, manipulating the locale parameter. The CVSS vector indicates no privileges and no user interaction are required.
Exploitation
Listed in CISA KEV since 2022-03-25 with known ransomware campaign use, and EPSS 30-day probability is 0.99721 (99.95th percentile). A public exploit reference is tagged in the record.
What to do
- Apply the vendor update per Adobe security bulletin APSB10-18; upgrade ColdFusion to a supported fixed release.
- If patching is not immediately possible, restrict network access to CFIDE/administrator paths to trusted management hosts only.
- Remove or block the ColdFusion administrator console from internet-facing exposure.
- Rotate credentials and secrets stored in ColdFusion configuration files that may have been exposed.
- Monitor for and investigate any prior traversal attempts against the listed administrator pages.
Detection
- Search web logs for requests to CFIDE/administrator pages (mappings.cfm, logging/settings.cfm, datasources/index.cfm, j2eepackaging/editarchive.cfm, enter.cfm) containing traversal sequences in the locale parameter.
- Alert on encoded traversal patterns such as ../, ..%2f or %2e%2e%2f in requests to ColdFusion administrator endpoints.
- Review file access and process telemetry for unexpected reads of ColdFusion configuration files by the web service account.
- Correlate any hits with outbound connections or follow-on activity indicating credential use.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-2861 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Adobe ColdFusion Directory Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://securityreason.com/securityalert/8137 | Broken Link |
| http://securityreason.com/securityalert/8148 | Broken Link |
| http://www.adobe.com/support/security/bulletins/apsb10-18.html | Not ApplicableVendor Advisory |
| http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/ | Exploit |
| http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 | Broken Link |
| http://securityreason.com/securityalert/8137 | Broken Link |
| http://securityreason.com/securityalert/8148 | Broken Link |
| http://www.adobe.com/support/security/bulletins/apsb10-18.html | Not ApplicableVendor Advisory |
| http://www.gnucitizen.org/blog/coldfusion-directory-traversal-faq-cve-2010-2861/ | Exploit |
| http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-07 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-2861 | US Government Resource |
Track CVE-2010-2861 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2861), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.