LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2013-0629: Adobe ColdFusion Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Sep 7, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2013-0629 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Sep 7, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

CVE-2013-0629 is a directory traversal vulnerability in Adobe ColdFusion that can let an unauthorized user reach restricted directories on the server. For IT and security teams running ColdFusion, this matters because successful abuse can expose configuration files, application data, or other sensitive content that should remain inaccessible, increasing the risk of further compromise.

Public detail is limited to the CISA summary and the stated weakness class. Confirm exact affected builds, fixed releases, and any configuration prerequisites directly against the vendor advisory before acting.

How it works

The issue is classified under CWE-264 (Permissions, Privileges, and Access Controls). In directory-traversal flaws of this type, an attacker supplies crafted input—commonly path elements that reference parent directories—so that the application resolves a location outside the intended restricted area. When the ColdFusion component that handles the request fails to enforce proper path canonicalization or access checks, the result can be unauthorized read access to files or directories that the application should not serve.

No exploit mechanics, payloads, or specific request patterns are provided in the available facts. Treat any public proof-of-concept claims with caution and validate behavior only in a controlled lab against the vendor’s description. The practical outcome described by CISA is straightforward: an unauthorized user may gain access to restricted directories.

Am I affected? How to find it in your systems

Adobe ColdFusion is typically deployed as an application server for web and intranet applications, often fronted by a web server and listening on HTTP/HTTPS ports. It may run on Windows or Linux hosts in data centers, cloud VMs, or development environments that were never decommissioned.

How to remediate

Patch first. Apply the updates issued by Adobe for this vulnerability exactly as described in the vendor advisory and follow CISA’s required action: apply updates per vendor instructions. After patching, verify that the fixed version is running and that the previously vulnerable endpoints no longer accept traversal-style requests.

Additional hardening appropriate to this weakness class includes:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the official patch. Schedule the update as soon as operationally feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to data breaches. If you have evidence of successful traversal or unauthorized file access, follow your incident-response process: isolate affected systems, preserve logs, assess what directories or files may have been read, and determine whether credentials or sensitive data were present. Known ransomware use is not documented for this CVE. As a routine check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · ColdFusion
WeaknessCWE-264
Added to CISA KEVMar 7, 2022
Federal patch deadlineSep 7, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities