PT-2021-5986 · Adobe · Experience Manager

Published

2021-12-14

·

Updated

2022-01-19

·

CVE-2021-43762

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.10.0 and below Adobe Experience Manager's Cloud Service offering
Description The issue is related to insufficient input validation, which could allow a remote attacker to bypass security controls. Sensitive areas of the web application may be exposed through exploitation of this issue.
Recommendations For Adobe Experience Manager versions 6.5.10.0 and below, update to a version above 6.5.10.0 to resolve the issue. For Adobe Experience Manager's Cloud Service offering, contact the vendor for specific guidance on resolving the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the Cloud Service offering.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00505
CVE-2021-43762

Affected Products

Experience Manager