7.5
CVE-2022-42340
- EPSS 3.02%
- Veröffentlicht 14.10.2022 20:15:17
- Zuletzt bearbeitet 21.11.2024 07:24:47
- Quelle psirt@adobe.com
- CVE-Watchlists
- Unerledigt
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Input Validation vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Coldfusion Version2018 Update-
Adobe ≫ Coldfusion Version2018 Updateupdate1
Adobe ≫ Coldfusion Version2018 Updateupdate10
Adobe ≫ Coldfusion Version2018 Updateupdate11
Adobe ≫ Coldfusion Version2018 Updateupdate12
Adobe ≫ Coldfusion Version2018 Updateupdate13
Adobe ≫ Coldfusion Version2018 Updateupdate14
Adobe ≫ Coldfusion Version2018 Updateupdate2
Adobe ≫ Coldfusion Version2018 Updateupdate3
Adobe ≫ Coldfusion Version2018 Updateupdate4
Adobe ≫ Coldfusion Version2018 Updateupdate5
Adobe ≫ Coldfusion Version2018 Updateupdate6
Adobe ≫ Coldfusion Version2018 Updateupdate7
Adobe ≫ Coldfusion Version2018 Updateupdate8
Adobe ≫ Coldfusion Version2018 Updateupdate9
Adobe ≫ Coldfusion Version2021 Update-
Adobe ≫ Coldfusion Version2021 Updateupdate1
Adobe ≫ Coldfusion Version2021 Updateupdate2
Adobe ≫ Coldfusion Version2021 Updateupdate3
Adobe ≫ Coldfusion Version2021 Updateupdate4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.02% | 0.861 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@adobe.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.