PT-2021-7668 · Adobe · Coldfusion

Published

2021-10-11

·

Updated

2022-10-18

·

CVE-2022-42340

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier)
Description The issue is caused by improper input validation, which could result in arbitrary file system read. Exploitation of this issue does not require user interaction. This allows a remote attacker to disclose protected information.
Recommendations For Adobe ColdFusion versions Update 14 and earlier, update to a version later than Update 14. For Adobe ColdFusion versions Update 4 and earlier, update to a version later than Update 4. As a temporary workaround, consider restricting input validation to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-01163
CVE-2022-42340

Affected Products

Coldfusion