High severity7.5NVD Advisory· Published Oct 14, 2022· Updated Jun 17, 2026
CVE-2022-42341
CVE-2022-42341
Description
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary file system read. Exploitation of this issue does not require user interaction.
Affected products
22Update 14 (and earlier) and Update 4 (and earlier)+ 21 more
- (no CPE)range: Update 14 (and earlier) and Update 4 (and earlier)
- (no CPE)range: unspecified
- cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update13:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update14:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update2:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update3:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update4:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update5:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update6:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update7:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update8:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2018:update9:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2021:update1:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2021:update2:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2021:update3:*:*:*:*:*:*
- cpe:2.3:a:adobe:coldfusion:2021:update4:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- helpx.adobe.com/security/products/coldfusion/apsb22-44.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.