CVE-2022-38420: Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38420?
CVE-2022-38420 is a vulnerability in Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) that allows attackers to gain access to start/stop arbitrary services and cause application denial-of-service.
What is the severity of CVE-2022-38420?
CVE-2022-38420 has a severity rating of 7.5 out of 10, indicating a high severity.
How does CVE-2022-38420 impact Adobe ColdFusion?
CVE-2022-38420 can be exploited without user interaction to gain unauthorized access to start/stop arbitrary services, which can lead to application denial-of-service.
Which versions of Adobe ColdFusion are affected by CVE-2022-38420?
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by CVE-2022-38420.
How can I fix CVE-2022-38420?
To mitigate CVE-2022-38420, it is recommended to update Adobe ColdFusion to a version that includes the necessary security patches as provided by Adobe.