Adobe Experience Manager versions 6.5.13.0 (and earlier)...
Moderate severity
Unreviewed
Published
Sep 17, 2022
to the GitHub Advisory Database
•
Updated Jul 30, 2023
Description
Published by the National Vulnerability Database
Sep 16, 2022
Published to the GitHub Advisory Database
Sep 17, 2022
Last updated
Jul 30, 2023
Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a Violation of Secure Design Principles vulnerability that could lead to bypass the security feature of the encryption mechanism in the backend . An attacker could leverage this vulnerability to decrypt secrets, however, this is a high-complexity attack as the threat actor needs to already possess those secrets. Exploitation of this issue requires low-privilege access to AEM.
References