Vulnerability Name: | CVE-2022-42341 (CCN-237896) | ||||||||||||
Assigned: | 2022-10-11 | ||||||||||||
Published: | 2022-10-11 | ||||||||||||
Updated: | 2022-10-18 | ||||||||||||
Summary: | Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction. | ||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-611 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-42341 Source: XF Type: UNKNOWN adobe-coldfusion-cve202242341-info-disc(237896) Source: CCN Type: Adobe Security Bulletin APSB22-44 Security updates available for ColdFusion Source: MISC Type: Vendor Advisory https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |