Vulnerability record · CVE-2022-38423 · published 14 October 2022
CVE-2022-38423: Adobe ColdFusion path traversal allows information disclosure
Adobe · Coldfusion
Adobe ColdFusion Update 14 and earlier and Update 4 and earlier contain a path traversal flaw (CWE-22) that lets a pathname escape its restricted directory. Successful abuse discloses information from the server. The issue is rated medium severity with a CVSS 3.1 base score of 4.9.
Description
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in information disclosure. Exploitation of this issue does not require user interaction, but does require administrator privileges.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityThe flaw requires administrator privileges and only affects confidentiality, but it is remotely reachable and EPSS is high, so it warrants timely patching.
What it is
Adobe ColdFusion Update 14 and earlier and Update 4 and earlier contain a path traversal flaw (CWE-22) that lets a pathname escape its restricted directory. Successful abuse discloses information from the server. The issue is rated medium severity with a CVSS 3.1 base score of 4.9.
Impact
An attacker with administrator privileges can read files outside the intended directory, exposing configuration or other sensitive data. Confidentiality is fully impacted; integrity and availability are not.
Attack surface
Reachable over the network (AV:N) with low attack complexity and no user interaction. It requires high privileges, specifically administrator access, per the CVSS vector and description.
Exploitation
Not listed in CISA KEV and no public exploit tags appear in the references, which are only vendor advisories. EPSS is high at roughly 0.45 probability (98.7th percentile), suggesting elevated interest, but the record shows no confirmed exploitation.
What to do
- Apply the Adobe ColdFusion security update referenced in advisory APSB22-44 for the affected Update 14 and Update 4 branches.
- Restrict administrator access to ColdFusion administrative interfaces to trusted networks and accounts.
- Audit and reduce the number of accounts with ColdFusion administrator privileges.
- Monitor file access from the ColdFusion service account for reads outside expected web and application directories.
- Review ColdFusion logs for anomalous administrative requests involving file paths.
Detection
- Alert on ColdFusion administrator sessions or API calls that reference path traversal sequences such as ../ in file parameters.
- Monitor the ColdFusion service account for file reads outside its normal application and web root directories.
- Correlate administrative logins from unusual source IPs with subsequent file access events.
- Review ColdFusion and web server logs for requests to administrative endpoints containing encoded traversal patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | Vendor Advisory |
Track CVE-2022-38423 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-38423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.