PT-2020-5112 · Adobe · Experience Manager
Published
2020-09-08
·
Updated
2021-09-14
·
CVE-2020-9733
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Experience Manager versions prior to 6.5.5.0
Adobe Experience Manager versions prior to 6.4.8.1
Description
The issue is related to an AEM java servlet that executes with the permissions of a high privileged service user, potentially leading to read-only access to sensitive data in an AEM repository. The vulnerability is also associated with insufficient protection of the web page structure, which could allow a remote attacker to execute arbitrary JavaScript code in a browser and access protected information.
Recommendations
For versions prior to 6.5.5.0, update to a version that contains a fix for this issue.
For versions prior to 6.4.8.1, update to a version that contains a fix for this issue.
As a temporary workaround, consider restricting access to sensitive data in the AEM repository until a patch is available.
Fix
Improper Privilege Management
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Experience Manager