Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-04-23T16:49:39.021Z
Reserved: 2022-08-18T00:00:00.000Z
Link: CVE-2022-38418
Updated: 2024-08-03T10:54:03.691Z
Status : Modified
Published: 2022-10-14T20:15:12.507
Modified: 2024-11-21T07:16:26.210
Link: CVE-2022-38418
No data.
OpenCVE Enrichment
No data.
Weaknesses