CVE-2022-38421: Adobe ColdFusion Application Server Directory Traversal Remote Code Execution Vulnerability
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, but does require administrator privileges.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-38421?
CVE-2022-38421 is an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adobe ColdFusion that could result in arbitrary code execution.
How does CVE-2022-38421 affect Adobe ColdFusion?
CVE-2022-38421 affects Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier).
What is the severity of CVE-2022-38421?
CVE-2022-38421 has a severity rating of 7.2 (High).
How can CVE-2022-38421 be fixed?
To fix CVE-2022-38421, Adobe recommends updating to the latest version of ColdFusion.
Where can I find more information about CVE-2022-38421?
More information about CVE-2022-38421 can be found on the Adobe Security Bulletin APSB22-44.