CVE-2022-38418: Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38418?
CVE-2022-38418 is a vulnerability that affects Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier).
What is the severity of CVE-2022-38418?
CVE-2022-38418 has a severity score of 9.8 (Critical).
How does CVE-2022-38418 impact Adobe ColdFusion?
CVE-2022-38418 allows for Path Traversal, which can lead to arbitrary code execution in the context of the current user.
Which versions of Adobe ColdFusion are affected by CVE-2022-38418?
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by CVE-2022-38418.
How can I fix CVE-2022-38418?
To fix CVE-2022-38418, update to a version of Adobe ColdFusion that is not affected by this vulnerability.