PT-2020-5112 · Adobe · Experience Manager

Published

2020-09-08

·

Updated

2021-09-14

·

CVE-2020-9733

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions prior to 6.5.5.0 Adobe Experience Manager versions prior to 6.4.8.1
Description The issue is related to an AEM java servlet that executes with the permissions of a high privileged service user, potentially leading to read-only access to sensitive data in an AEM repository. The vulnerability is also associated with insufficient protection of the web page structure, which could allow a remote attacker to execute arbitrary JavaScript code in a browser and access protected information.
Recommendations For versions prior to 6.5.5.0, update to a version that contains a fix for this issue. For versions prior to 6.4.8.1, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to sensitive data in the AEM repository until a patch is available.

Fix

Improper Privilege Management

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05708
CVE-2020-9733

Affected Products

Experience Manager