The official community for ColdFusion.
Recently active
I’m converting a database from MS‑SQL to PostgreSQL and I need to change the calls to the Stored Procedures.I rewrote them in PostgreSQL, and when I try to execute them, it returns an error saying that the procedure’s cursor does not exist.For example, a call that used to be:<cfquery name="getApp_Version"> EXEC sp_app_version;</cfquery>Was changed to:<cfquery name="getApp_Version"> BEGIN; CALL "public"."sp_app_version"('c1'); FETCH NEXT FROM c1; COMMIT;</cfquery>And the following message appes:ERROR: cursor "c1" does not existI was advised to convert the procedures into functions to solve the problem, but there are too many procedures to rewrite.Is there a way to call Stored Procedures in PostgreSQL without getting this error?
I am trying to use org.jaudiotagger.audio.AudioFileIO to read some tags in mp3 files. The following lines work correctly: fileObj = createObject("java", "java.io.File").init(lsFileNameWithPath);audioFileIO = createObject("java", "org.jaudiotagger.audio.AudioFileIO");audioFile = audioFileIO.read(fileObj);audioHeader = audioFile.getAudioHeader();bitrate = audioHeader.getBitRate();writeOutput("The audio file bitrate is: " & bitrate);writeOutput(AudioHeader);but If I try anything with tags such as:Tag tag = audioFile.getTag(); orlsArtist = audioFile.getTag().getFirst(FieldKey.ARTIST);I get error messages. In the first case the error message is “ Variable TAG is undefined.“ and in the second case the error message is “ Variable FIELDKEY is undefined”Any suggestions as to what I am doing wrong?
Weak Session Token Randomness vulnerability found during pentesting in ColdFusion 2023 Administrator During a recent penetration test, we identified a vulnerability related to weak session token randomness in ColdFusion 2023, specifically impacting the Administrator interface. Our analysis indicates that only about 6 out of 80 characters in the session cookie exhibit sufficient randomness, which poses a risk to session security.Could you please advise if ColdFusion 2023 offers any configuration options or best practices to enhance the randomness and security of session tokens for the Administrator? Is it possible to customize the session ID generator or enable a stronger session management mechanism?Any guidance or recommendations to mitigate this vulnerability would be greatly appreciated.Thank you in advance for your support!
I’m setting up a SAML integration in ColdFusion 2021. It works fine, but when I’m in the Administrator if I check the “Want Assertions Signed” checkbox but don’t fill out Signing Keystore information and save it, whenever I try to edit the SP it always fails saying the keystore…. is undefined. My understanding is that “Want Assertions Signed” means the IDP signs the request it sends. Inside of the IDP I set up the Signing Certificate so it decrypts the response successfully. This all works fine, it’s just I can’t get in to edit the SP after setting it up. Entra provides the certificate and has options to sign the request and assertion, so I assume I don’t have to set up that certificate in my SP, but I do have to add it to the IDP so it knows how to verify the SAML response. Is this wrong? If I leave “Want Assertions Unchecked” what does that do for my process? Thank you.
Hello CF Community, We have a bit of an unusual situation, On one of the servers we have the log4j files which i do not see on the other servers. We have a security issue and the core-2.13.3 needs to be removed. We are running the CF2021 Updated to update 18 on all nodes. Only one of the nodes is showing the extra files in the CF/jre/lib folder. How can i go about safely removing the core2.13.3 file for log4j. Can i simply remove and if so what should i be on the look out for in terms of failures?
Hello, everyone. Still have not had a chance to do anything with my last issue (still ongoing), and now we have more issues. They just keep cropping up. The most critical, however, is that our SA is getting 400 errors trying to access CF Admin. I’m trying to get as much information from our SA as possible. He’s checking logs, as I type this. I’m hoping he can get me some details for me to post. Right now, all I have is what appears in the browser when he tries to access CF Admin. BAD REQUESTYour browser set a request that this server could not understand.Additionally, a 400 Bad Request error was encountered while trying to use an ErrorDocument to handle the request. As soon as our SA passes to me what he finds in the logs, I’ll post them here. V/r,WolfShade
Hello!This is a continuation of a question I posed days prior to the upgrade of the Adobe forums. The post never reappeared on the new forums, and so I’m reposting this update afresh.My original question centered on how to configure IIS websites such that all users would be required to go through the API Manager to access the API. BKBK responded with details on how to set up a reverse proxy. Mission accomplished. I now have two IIS sites:APIMGR.mysite.com is the gateway (reroutes traffic to API.mysite.com) API.mysite.com is the backend (rejects direct traffic; permits incoming traffice only from APIMGR.mysite.com)My question now is, what settiings, if any, in the API Manager Administrator (or in the Portal) need to change, to accommodate this reverse proxy setup? Specifically, do these default settings for the Host or the Domain URL need to change, or does the API administrator still serve up requests via the default localhost / localhost:port configuration? Thanks in advance for the a
Can anyone tell me what happens when a ColdFusion 2023 Enterprise license is used on more servers (or CPUs or whatever) than Adobe thinks are covered by the license? I would not deliberately overuse a license, but because previous communication with Adobe about licensing has been far from clear, and the fact that I am not in our company’s licensing department, as well as the fact that Adobe’s stance on allowing (or not) a license to be used on a dev servers if licensing has been purchased for a prod server, it’s hard to be 100% sure that issues won’t arise.We have a UAT server and I’m almost sure our existing licensing will accommodate it, but if I apply the serial number and it isn’t covered, what will happen - Something as clear as a notification on attempt, or something much worse, like our PROD server being silently downgraded to developer mode?Thanks!
I have a simple loop that is used to clean up old files within a directory:<cfdirectory action="list" name="qDir" directory="#variables.path#"><cfloop query="qDir"> <cfif qDir.Type eq "File"> <cfif DateDiff("h", qDir.DateLastModified, Now()) gt attributes.keep_for_hours> <cfset variables.full_file_path = variables.path & qDir.Name> <cfif FileExists(variables.full_file_path)> <cffile action="delete" file="#variables.full_file_path#"> </cfif> </cfif> </cfif></cfloop>This is on Linux where ColdFusion is running as apache.Recently a system scan process has been leaving behind files owned by root within the directory resulting in an error stating:“The file or directory <filename> provided as the Source is read-only. - The Delete cannot be performed.”While it’s true that the file is read-only, apache owns the directory the file is in and should still be able to delete the file.How do I go about encouragin
Load Balancer cannot tell when ColdFusion site is up or not due to logon pop-up.We have a load balancer to ensure that if one of our ColdFusion services goes down, we switch all traffic to the other server.The problem we have is that we want to check the web site is responsive – not just that the service is running, as the ColdFusion Application Server service can be running but the web site does not respond.But when the Load Balancer checks the web page the Edge account logon popup appears, and confuses it as it thinks the site is running. This can be mimicked by entering the monitor page URL into Chrome incognito (networks team said if it works in Incognito, it will work in the Load Balancer).Is there any way to get this working?In IIS the main site is set up so we are automatically logged in via our window using Windows Authentication. The “monitor” site has Anonymous Authentication. In testing Chrome Incognito works for a simple html page (no account logon pop up), but account l
Environment: Windows-based, using ColdFusion 2023. When creating admin console “users,” has anyone setup external authentication (using LDAP) using groups instead of individual users? Due to a recently released ColdFusion STIG I’m now required to create admin console users who are externally authenticated (no local user accounts). In my case, that means using LDAP to authenticate the users from Active Directory (AD). My preference is to configure this using an AD group instead of individual users.I’m struggling trying to determine what data goes in what fields during the setup. I have the LDAP configured and verifying the connection. I’m using the correct LDAP filter in the Group Configuration field; I know it’s correct because when I test it using the CFLDAP tag, it returns the users who are assigned to the target group. But, in the User Manager (User Detail), the ‘User name’ field is required and I’m not sure what to enter. I’ve tried several different things, but always get the r
We are running CF-2021 Update-22 with IIS on Windows 2019. Suddenly today all Coldfusion sites started experiencing significant delays. Response times have increased to between 5 and 40 seconds, while they used to be within 100-200 ms. There have been no updates or changes on the server as far as I can see. Restarting or upgrading connectors didn't help, CPU usage is low and there is plenty of RAM and storage. Http and css files are served immediately, and Coldfusion debugger reports show that pages are still loading pretty fast: Total Execution Time is less than 100 ms. I didn't find any signs of the DoS attack.So the issue must be somewhere between IIS and Tomcat. In fact, isapi_redirect logs show more errors then before, like[Thu Feb 05 21:16:16.555 2026] [10156:7684] [info] ajp_process_callback::jk_ajp_common.c (2288): current reuse count is 192 of max reuse connection 300 and total endpoint count 400[Thu Feb 05 21:16:17.662 2026] [10156:13788] [error] start_response::jk_isapi_plug
Hello everybody!I am working on removing all my inline JS codes. As an exapmle I've created a simple coldfusion (CF) template with a button. In a separate javascript file I define the function which is called when the button is pressed. This function is to have an argument through which I pass a value to be displayed. test4.cfm: <cfscript> Variables.sTest = "ha-ha-ha";</cfscript><!DOCTYPE html><html> <head> <meta http-equiv="Content-Security-Policy" content="script-src 'self'"> <script> var sValFromCF = "<cfoutput>#Variables.sTest#</cfoutput>"; </script> <script src="JS_test4.js" defer> </script> </head> <body> <INPUT TYPE="button" name="sBtn4" id="sBtn4" value="Click me4"> </body></html>JS_test4.js: <!-- Begin hiding contents from older browsersdocument.addEventListener ('DOMContentLoaded', () => { document.getElementById("sBtn4").addEventListener("cli
This happened after I installed all 6 patches for Cold Fusion 2025, in order. I rebooted the system but still got the same error.
I would like to switch from CF 2016 to CF 2025. I have already installed the developer edition of the latest CF 2025 version.Could anyone post me a link to a migration guide or/and provide other useful information about the migration steps to do? Thanks for any help!
Hello. Let's say that I have an API running at https://api.mysite.com/rest/api/customerID/12345 which is available to anyone with the link. Joe User can go to that site right now and pull that payload, but now, I want to lock it down through the API Manager. I have everything set up in the API Manager (Server discovery, REST API import, REST Playground Config, Publisher/Subscriber setup, Authentication (using apiKey), SLA Creation, Rate Limiting, and so on, in order to manage these requests. Everything looks good. I think my question is simple: What's to stop Joe User, or even Joe Subscriber, from circumventing the apikey requirement and hammer away at my api with impunity? Does one pass through the API Key with each request, or how does it work? How do I prevent casual usage of visitors continuing to hit my API by just going to https://api.mysite.com/rest/api/customerID/12345? Brian Sappey's webinar series has made API creation and management a breeze,
I'm working on building an interface with ID.me. I am currently getting back a valid JWT from the ID.me API (it successfully decodes using JWT.IO) but I'm having trouble decoding it in ColdFusion. The CF function VerifySignedJWT has three required parameters and, I believe, I am having trouble with the second parameter signOptions. The CF documentation indicates this parameter should be a strcut containing the key, KeyPair, JWK-JSON Web Keyset URL or file or string, Keystore file, keystore password, keystore alias.I am retrieveing the key array from the JWK-JSON Web Keyset URL (ID.me's well known endpoint) but am stuck here. When I attempt to decode using <cftry> <cfset payload = VerifySignedJWT(idToken, key, c)> <cfcatch type="any"> &n
Keep getting. java.sql.SQLException: Index -1 out of bounds for length 0 Please help. I cleared Felix -cache, tried Odbc11.jar in ..\lib folder restarted no difference. running out of options before rollback. ty community. I was on call with Adobe over 1 hour they hung up. No respnse from CFsup... email Jose Duenas Lead systems Kaiser
I am running a developer version of ColdFusion 2025 Version 2025,0,06,331564 on my MacBook Pro MacOS Tahoe 26.2 (25C56). I used the ZIP installer to install it. When ever I try to use the CZIP tag in CFML or function in CFSCRIPT I get the following error:Cannot find implementation class coldfusion.tagext.zip.ZipTag for the zip tag. I have restarted everything. I have run cfpm.sh with `purgecache`. I have deleted the felixcache completely and restarted. I have run cfpm.sh with `install all`. None of that has resolved it. I do have the zip package installed. Do I need to recompilie the coldfusion binary? The reason I have not yet just tired to unintall and reinstall is becuase I have spent a lof ot time getting SSL Vhosts working with the default install of Apache on MacOS and ColdFusion so that apache properly hands off ColdFusion requests. I am wary of running the uninstall script because I assume it will remove the jk_mod connector
Tenable Security scan has identified Fileupload-1.5.jar as a high Vulnerability. Is this a false positive ? C:\ColdFusion2023\bundles\repo\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path : C:\ColdFusion2023\bundles\updateinstallers\hotfix-packages-cf2023-016-330828\repo\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path : C:\ColdFusion2023\bundles\updateinstallers\hotfix-packages-cf2023-016-330828\repo\commons-fileupload-1.4.jar Installed version : 1.4 Fixed version : 1.6 Path : C:\ColdFusion2023\cfusion\lib\bundleaxis\commons-fileupload-1.5.jar Installed version : 1.5 Fixed version : 1.6 Path :
We are pleased to inform you that we've released security updates for ColdFusion 2025 and 2023 releases. For more information, see the respective tech notes: ColdFusion (2025 release) Update 6 ColdFusion (2023 release) Update 18 What's new and changed The releases address CVE-2025-66516, a critical XXE in Apache Tika libraries. Adobe strongly recommends that you apply this update as soon as possible. Note that this update is cumulative and includes fixes from previous updates. This update upgrades the embedded Apache Tika libraries, providing the latest security and stability enhancements, while preserving existing application behavior. View the tech notes, and the security bulletin, APSB26-12, for more information. Download the updates ColdFusion 2025 updates ColdFusion 2023 updates Docker and CFFiddle CFFiddle is now updated with the changes The Docker images are also updated: Docker Hub - ColdFusion Images Amazon ECR - ColdFusion Image
Hi everyone,After applying ColdFusion 2023 Update 17 in our ACPT environment, all of our datasources suddenly stopped verifying. The CF Administrator now shows this error: Connection verification failed for data source: <name> java.sql.SQLException: The oracle package is not installed. You can install the package through the CLI package manager (cfpm.bat) by running the command: install oracle.This is happening on all Oracle and SQL Server datasource. However,Running cfpm list confirms that both oracle and sqlserver packages are installed, e.g.:oracle, version : 2023.0.11.330706 sqlserver, version : 2023.0.05.330608Despite this, ColdFusion Admin continues to report the driver as “not installed”. I would like to ask, Is this a known issue where CFPM installs the Oracle package but CF Admin fails to register or load the new driver? and what is the recommended/supported way to ensure ColdFusion Admin maps Oracle datasources after Update 17? Any guidance or confir
Good morning, everyone. We recently applied HF 17 to our servers, and now we have hundreds of error emails flowing in alerting us to an onRequestStart error. Exception java.lang.NullPointerException [in thread "ajp-nio-214.3.xx.xxx-8022-exec-7"] java.lang.ExceptionInInitializerError: Exception java.lang.NullPointerException [in thread "ajp-nio-214.3.xx.xxx-8022-exec-7"] at oracle.jdbc.driver.DynamicByteArray$1.run(DynamicByteArray.java:1133) at java.base/java.security.AccessController.doPrivileged(AccessController.java:318) at oracle.jdbc.driver.DynamicByteArray. We have tried rolling back to backups created before the HF was applied, but we are still getting an error. The file/line is application.cfc, and is in the middle of a query at a CFQUERYPARAM that has "#cgi.remote_addr#" as the value. Has anyone run across this? V/r, WolfShade UPDATE: We have restored from a backup from ten days ago, and seem to be working, now. But we wil
Hi, I bought HS ( Homesite ) 5.5 many years ago and over time I have unfortunately lost the installation file, the one where it asks for your serial which I still have, I have searched for the software but none of the software I have found asks for the serial, can anyone point me in the right direction or even kindly share their installation file. Thanks. David
We are pleased to inform you that we've released security updates for ColdFusion 2025, 2023, and 2021 releases. For more information, see the respective tech notes: ColdFusion (2025 release) Update 5 ColdFusion (2023 release) Update 17 ColdFusion (2021 release) Update 23 End of core support for ColdFusion 2021 update release Adobe ColdFusion (2021 release) Update 23 marks the end of core support for ColdFusion 2021 update releases. Adobe ColdFusion (2021 release) Update 23 is the final update, as this version reached its end of core support on November 10, 2025. After this update, no further core updates will be provided for this version. What's new and changed The updates includes important security fixes that mitigate vulnerabilities related to arbitrary file system write, arbitrary file system read, arbitrary code execution, and security feature bypass. The updates also include: New JVM flags Changes to serialfilter CAR migration changes Tomcat upgrade Bug fixes and k
Remix with Firefly Community Gallery
Thousands of free creations to fall in love with and remix in Firefly.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.