PT-2022-6004 · Adobe · Campaign
Published
2022-12-13
·
Updated
2022-12-21
·
CVE-2022-42343
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Campaign versions 7.3.1 and earlier
Adobe Campaign versions 8.3.9 and earlier
Description
The issue is related to a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction. The vulnerability is associated with insufficient checking of incoming requests, which may allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For Adobe Campaign versions 7.3.1 and earlier, update to a version later than 7.3.1 to resolve the issue.
For Adobe Campaign versions 8.3.9 and earlier, update to a version later than 8.3.9 to resolve the issue.
As a temporary workaround, consider restricting access to the application to minimize the risk of exploitation.
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Campaign