CVE-2022-38423: Adobe ColdFusion Application Server Directory Traversal Information Disclosure Vulnerability
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction, but does require administrator privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-38423?
CVE-2022-38423 refers to an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Adobe ColdFusion that could lead to information disclosure.
What versions of Adobe ColdFusion are affected by CVE-2022-38423?
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by this vulnerability.
Is user interaction required to exploit CVE-2022-38423?
No, exploitation of this vulnerability does not require user interaction.
What is the severity rating of CVE-2022-38423?
CVE-2022-38423 has a severity rating of 4.9 (medium).
Where can I find more information about CVE-2022-38423?
You can find more information about CVE-2022-38423 on the Adobe website at the following link: [link](https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html).