PT-2021-9729 · Bloomreach · Bloomreach Experience Manager

Published

2021-03-11

·

Updated

2021-07-21

·

CVE-2020-14987

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Bloomreach Experience Manager (brXM) versions 4.1.0 through 14.2.2
Description An issue in the Bloomreach Experience Manager allows remote attackers to execute arbitrary code due to a mishandling of the capability for administrators to write and run Groovy scripts within the updater editor. This can be exploited by using an AST transforming annotation such as @Grab.
Recommendations For versions 4.1.0 through 14.2.2, consider disabling the capability for administrators to write and run Groovy scripts within the updater editor as a temporary workaround until a patch is available. Restrict access to the updater editor to minimize the risk of exploitation. Avoid using AST transforming annotations such as @Grab in the Groovy scripts until the issue is resolved.

Exploit

Fix

Missing Authorization

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14987

Affected Products

Bloomreach Experience Manager