Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-38421


Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.


Published

2022-10-14T20:15:13.103

Last Modified

2024-11-21T07:16:26.613

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2018 Yes
Application adobe coldfusion 2021 Yes
Application adobe coldfusion 2021 Yes
Application adobe coldfusion 2021 Yes
Application adobe coldfusion 2021 Yes
Application adobe coldfusion 2021 Yes

References