PT-2021-6638 · Adobe · Experience Manager
Published
2021-09-14
·
Updated
2021-10-01
·
CVE-2021-40712
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Experience Manager versions 6.5.9.0 and earlier
Description
The issue is related to improper input validation via the
path parameter, allowing an authenticated attacker to send a malformed POST request and achieve server-side denial of service. This can be exploited by a remote attacker to cause a denial of service.Recommendations
For Adobe Experience Manager versions 6.5.9.0 and earlier, consider restricting access to the vulnerable
path parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the path parameter in POST requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Experience Manager