PT-2021-6638 · Adobe · Experience Manager

Published

2021-09-14

·

Updated

2021-10-01

·

CVE-2021-40712

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.9.0 and earlier
Description The issue is related to improper input validation via the path parameter, allowing an authenticated attacker to send a malformed POST request and achieve server-side denial of service. This can be exploited by a remote attacker to cause a denial of service.
Recommendations For Adobe Experience Manager versions 6.5.9.0 and earlier, consider restricting access to the vulnerable path parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the path parameter in POST requests until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01954
CVE-2021-40712

Affected Products

Experience Manager