CVE-2022-38420: high-severity vulnerability in Adobe ColdFusion
Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Adobe ColdFusion contains hard-coded credentials that attackers can use to start or stop services without permission, causing the application to crash or become unavailable. No user action is needed for the attack to work.
ColdFusion versions Update 14 and earlier (2016 branch) and Update 4 and earlier (2018 branch) expose hard-coded credentials (CWE-798) accessible to local or network attackers. Exploitation allows arbitrary service manipulation leading to denial-of-service; no authentication bypass required, only access to the vulnerable system.
In the same product, most dangerous first.