CERT-In Vulnerability Note
CIVN-2022-0483
Multiple Vulnerabilities in Adobe Experience Manager
Original Issue Date:December 20, 2022
Severity Rating: MEDIUM
Software Affected
- Adobe Experience Manager (AEM) Cloud Service (CS)
- Adobe Experience Manager (AEM) versions 6.5.14.0 and earlier
Overview
Multiple vulnerabilities have been reported in Adobe Experience Manager (AEM) which could be exploited by an attacker to execute arbitrary code or bypass security restrictions on the target system.
Description
These vulnerabilities exist in Adobe Experience Manager (AEM) due to an error while neutralizing user-controllable input (cross-site scripting), improper access control or an error while redirecting a URL to an untrusted site.
Successful exploitation of these vulnerabilities could allow the attacker to execute arbitrary code or bypass security restrictions on the target system.
Solution
Apply appropriate patches as mentioned in Adobe Security Update
https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html
Vendor Information
Adobe
https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html
References
Adobe
https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html
CVE Name
CVE-2022-42345
CVE-2022-42346
CVE-2022-30679
CVE-2022-42348
CVE-2022-42349
CVE-2022-42350
CVE-2022-42351
CVE-2022-42352
CVE-2022-35693
CVE-2022-42354
CVE-2022-35694
CVE-2022-42356
CVE-2022-42357
CVE-2022-35695
CVE-2022-35696
CVE-2022-42360
CVE-2022-42362
CVE-2022-42364
CVE-2022-42365
CVE-2022-42366
CVE-2022-42367
CVE-2022-44462
CVE-2022-44463
CVE-2022-44465
CVE-2022-44466
CVE-2022-44467
CVE-2022-44468
CVE-2022-44469
CVE-2022-44470
CVE-2022-44471
CVE-2022-44473
CVE-2022-44474
CVE-2022-44488
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|