PT-2021-6647 · Adobe · Experience Manager

Published

2021-06-08

·

Updated

2025-09-19

·

CVE-2021-28627

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Experience Manager versions 6.5.8.0 and below Adobe Experience Manager Cloud Service offering
Description The issue is related to insufficient validation of incoming requests, allowing an authenticated attacker to leverage a Server-side Request Forgery to contact systems blocked by the dispatcher. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Experience Manager versions 6.5.8.0 and below, update to a version above 6.5.8.0 to resolve the issue. For Adobe Experience Manager Cloud Service offering, contact the vendor for specific guidance on resolving the issue. As a temporary workaround, consider restricting access to the dispatcher to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01963
CVE-2021-28627

Affected Products

Experience Manager