PT-2021-5517 · Adobe · Experience Manager+1

Published

2021-12-14

·

Updated

2022-01-19

·

CVE-2021-40722

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.10.0 and below AEM Forms Cloud Service offering
Description The issue is related to an XML External Entity (XXE) injection vulnerability due to improper restriction of XML external entity references. This could allow a remote attacker to execute arbitrary code. The vulnerability may be exploited to achieve remote code execution (RCE).
Recommendations For Adobe Experience Manager versions 6.5.10.0 and below, update to a version that includes a fix for this issue. For AEM Forms Cloud Service offering, apply the necessary patch or configuration changes as recommended by the vendor to mitigate the XML External Entity (XXE) injection vulnerability.

Fix

RCE

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06367
CVE-2021-40722

Affected Products

Aem Forms Cloud Service
Experience Manager