CVE-2022-38420
Adobe ColdFusion Use of Hard-coded Credentials Application denial-of-service
In short
Adobe ColdFusion contains hard-coded credentials that attackers can use to start or stop services without permission, causing the application to crash or become unavailable. No user action is needed for the attack to work.
Technical detail
ColdFusion versions Update 14 and earlier (2016 branch) and Update 4 and earlier (2018 branch) expose hard-coded credentials (CWE-798) accessible to local or network attackers. Exploitation allows arbitrary service manipulation leading to denial-of-service; no authentication bypass required, only access to the vulnerable system.
Summary generated and translated by AI from the official description.
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Use of Hard-coded Credentials vulnerability that could result in application denial-of-service by gaining access to start/stop arbitrary services. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
Adobe · ColdFusionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →