← back
CVE-2022-38421

Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability

CVSS 7.2 HIGHEPSS 79.2%CWE-22
In short

Adobe ColdFusion contains a path traversal flaw that allows an administrator to execute arbitrary code on the server. An attacker with admin access can bypass directory restrictions and run malicious commands.

Technical detail

CWE-22 path traversal vulnerability in Adobe ColdFusion Update 14 or earlier (and Update 4 or earlier) allows authenticated administrators to escape directory restrictions and achieve remote code execution in the context of the application user. Exploitation requires valid admin credentials; no user interaction needed.

Summary generated and translated by AI from the official description.
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · ColdFusion

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →