CRITICAL
Adobe ColdFusion ODBC Agent Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Oct 14, 2022
9.8
CRITICALCVSS 3.1
EPSS 72.21%
Description
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.
Affected products
-
Affected
- ≥ unspecified, ≤ CF2018u14
- ≥ unspecified, ≤ CF2021U4
- ≥ unspecified, ≤ None
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Adobe | ColdFusion | unknown | Affected
|
OR
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2021
- 2021
- 2021
- 2021
- 2021
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38566 Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-38566 | Advisory | |
| https://helpx.adobe.com/security/products/coldfusion/apsb22-44.html | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Oct 14, 2022
Updated Apr 23, 2025
Reserved Jul 12, 2022
Link CVE-2022-35690
CISA Vulnrichment
Updated Apr 23, 2025
Red Hat
No data
GitHub
No data