CERT-In Vulnerability Note
CIVN-2020-0434
Multiple vulnerabilities in Adobe Experience Manager
Original Issue Date:December 11, 2020
Severity Rating: HIGH
Software Affected
- Adobe experience manager CS
- Adobe experience manager version 6.5.6.0 and earlier
- Adobe experience manager version 6.4.8.2 and earlier
- Adobe experience manager version 6.3.3.8 and earlier
- AEM Forms Service Pack 6 add-on package for AEM 6.5.6.0
- AEM Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2)
Overview
Multiple vulnerabilities have been reported in Adobe Experience manager which could allow a remote attacker to execute arbitrary code, gain elevated privileges or perform cross-site scripting attack on a targeted system.
Description
1. Server-Side Request Forgery (SSRF)
(
CVE-2020-24444
)
This vulnerability exists in Adobe Experience manager due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to open a specially crafted HTTP request. Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
2. Cross-site Scripting (Stored) vulnerability
(
CVE-2020-24445
)
This vulnerability exists in Adobe Experience manager due to insufficient sanitization of user supplied data. An attacker could exploit this vulnerability by injecting malicious scripts into vulnerable form fields which will be executed when the user browses the page containing the vulnerable field. Successful exploitation of this vulnerability could allow the remote attacker to access sensitive information and perform phishing attack on the targeted system.
Solution
Apply appropriate updates as mentioned in Adobe Security Bulletins:
https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html
References
https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html
CVE Name
CVE-2020-24444
CVE-2020-24445
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|