Vulnerability record · CVE-2013-0631 · published 9 January 2013
CVE-2013-0631: Adobe ColdFusion information disclosure exploited in the wild
Adobe · Coldfusion
Adobe ColdFusion 9.0, 9.0.1 and 9.0.2 expose sensitive information through unspecified vectors. The flaw was exploited in the wild in January 2013, and the record gives no detail on the exact mechanism, so defenders must treat the exposure as real but poorly characterized.
Description
Adobe ColdFusion 9.0, 9.0.1, and 9.0.2 allows attackers to obtain sensitive information via unspecified vectors, as exploited in the wild in January 2013.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityIt is in CISA KEV with confirmed in-the-wild exploitation and a very high EPSS score, but the record lacks the technical detail needed to rate it critical.
What it is
Adobe ColdFusion 9.0, 9.0.1 and 9.0.2 expose sensitive information through unspecified vectors. The flaw was exploited in the wild in January 2013, and the record gives no detail on the exact mechanism, so defenders must treat the exposure as real but poorly characterized.
Impact
An unauthenticated remote attacker can read sensitive information from the affected ColdFusion server. The record does not specify which data is exposed, so the full confidentiality impact cannot be scoped from this entry alone.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The description does not identify the specific endpoint or request, so the exact entry point is unknown.
Exploitation
Listed in CISA KEV since 2022-03-07 and described as exploited in the wild in January 2013, with an EPSS 30-day probability of 0.659 (99.2nd percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor updates referenced in Adobe security advisory APSA13-01 / bulletin APSB13-03, or upgrade off the unsupported 9.0.x line.
- If ColdFusion 9.0.x cannot be patched, isolate it behind a reverse proxy or WAF and restrict access to trusted networks only.
- Remove or block public exposure of ColdFusion administrative and diagnostic interfaces.
- Rotate credentials and secrets that may have been readable from the server, since the exposed data is unspecified.
- Monitor vendor and CISA guidance for the specific vector, which this record does not provide.
Detection
- Review web and ColdFusion logs for anomalous unauthenticated requests returning unusually large or unexpected responses.
- Alert on access to ColdFusion administrative or diagnostic paths from untrusted source IPs.
- Hunt for known exploitation patterns against ColdFusion 9.0.x from threat intel feeds, since the record gives no signature.
- Correlate outbound connections from ColdFusion hosts with data exfiltration indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2013-0631 to the Known Exploited Vulnerabilities catalog on 7 March 2022 as "Adobe ColdFusion Information Disclosure Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 7 September 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| http://www.adobe.com/support/security/advisories/apsa13-01.html | Vendor Advisory |
| http://www.adobe.com/support/security/bulletins/apsb13-03.html | Not Applicable |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2013-0631 | US Government Resource |
Track CVE-2013-0631 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-0631), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.