PT-2021-5517 · Adobe · Experience Manager+1
Published
2021-12-14
·
Updated
2022-01-19
·
CVE-2021-40722
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Experience Manager versions 6.5.10.0 and below
AEM Forms Cloud Service offering
Description
The issue is related to an XML External Entity (XXE) injection vulnerability due to improper restriction of XML external entity references. This could allow a remote attacker to execute arbitrary code. The vulnerability may be exploited to achieve remote code execution (RCE).
Recommendations
For Adobe Experience Manager versions 6.5.10.0 and below, update to a version that includes a fix for this issue.
For AEM Forms Cloud Service offering, apply the necessary patch or configuration changes as recommended by the vendor to mitigate the XML External Entity (XXE) injection vulnerability.
Fix
RCE
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aem Forms Cloud Service
Experience Manager