← back
CVE-2022-38420

Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service

CVSS 7.5 HIGHEPSS 44.0%CWE-798
In short

Adobe ColdFusion contains hard-coded credentials that attackers can use to start or stop services without permission, causing the application to crash or become unavailable. No user action is needed for the attack to work.

Technical detail

ColdFusion versions Update 14 and earlier (2016 branch) and Update 4 and earlier (2018 branch) expose hard-coded credentials (CWE-798) accessible to local or network attackers. Exploitation allows arbitrary service manipulation leading to denial-of-service; no authentication bypass required, only access to the vulnerable system.

Summary generated and translated by AI from the official description.
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Adobe · ColdFusion

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →