PT-2021-9729 · Bloomreach · Bloomreach Experience Manager
Published
2021-03-11
·
Updated
2021-07-21
·
CVE-2020-14987
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Bloomreach Experience Manager (brXM) versions 4.1.0 through 14.2.2
Description
An issue in the Bloomreach Experience Manager allows remote attackers to execute arbitrary code due to a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. This can be exploited by using an AST transforming annotation such as
@Grab.Recommendations
For versions 4.1.0 through 14.2.2, consider disabling the capability for administrators to write and run Groovy scripts within the updater editor as a temporary workaround until a patch is available. Restrict access to the updater editor to minimize the risk of exploitation. Avoid using AST transforming annotations such as
@Grab in the Groovy scripts until the issue is resolved.Exploit
Fix
Missing Authorization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bloomreach Experience Manager