← Back to browse · API

CVE-2022-38420

Severity
HIGH
CVSS
7.5
EPSS
0.44021
Risk score
45.41
CISA KEV
No
PoC
No
Published
2022-10-14
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-41005, GHSA-GMGX-CJ5G-7V52
Products
Adobe:ColdFusion unspecified ≤CF2018u14, Adobe:ColdFusion unspecified ≤CF2021U4, Adobe:ColdFusion unspecified ≤None
Sources
euvd EUVD-2022-41005

Description

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.

References