Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
43Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.2epss 79%
exploitation probability
79%top 1% of all CVEs
observed exploitation
nono source reports it
In short
Adobe ColdFusion contains a path traversal flaw that allows an administrator to execute arbitrary code on the server. An attacker with admin access can bypass directory restrictions and run malicious commands.
Technical detail
CWE-22 path traversal vulnerability in Adobe ColdFusion Update 14 or earlier (and Update 4 or earlier) allows authenticated administrators to escape directory restrictions and achieve remote code execution in the context of the application user. Exploitation requires valid admin credentials; no user interaction needed.
Summary generated and translated by AI from the official description.
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · ColdFusion