CVE-2022-38422: Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38422?
The severity of CVE-2022-38422 is high. It has a severity value of 7.5.
Which versions of Adobe ColdFusion are affected by CVE-2022-38422?
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by CVE-2022-38422.
What is the risk associated with CVE-2022-38422?
CVE-2022-38422 poses a risk of information disclosure due to an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability.
How can CVE-2022-38422 be exploited?
Exploitation of CVE-2022-38422 does not require user interaction.
Where can I find more information about CVE-2022-38422?
You can find more information about CVE-2022-38422 at the following reference: [link](https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html).