// For flags

CVE-2020-24444

Blind SSRF in Forms add-on for AEM

Severity Score

5.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the same network.

El add-on AEM Forms SP6 para AEM versión 6.5.6.0 y el paquete add-on Forms para AEM versión 6.4 Service Pack versión 8 Cumulative Fix Pack versión 2 (6.4.8.2), presentan una vulnerabilidad ciega de tipo Server-Side Request Forgery (SSRF). Esta vulnerabilidad podría ser explotada por un atacante no autenticado para recopilar información sobre los sistemas internos que residen en la misma red.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-08-19 CVE Reserved
  • 2020-12-10 CVE Published
  • 2023-08-26 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-918: Server-Side Request Forgery (SSRF)
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Adobe
Search vendor "Adobe"
Experience Manager Forms Add-on
Search vendor "Adobe" for product "Experience Manager Forms Add-on"
6.4.8.2
Search vendor "Adobe" for product "Experience Manager Forms Add-on" and version "6.4.8.2"
-
Affected
Adobe
Search vendor "Adobe"
Experience Manager Forms Add-on
Search vendor "Adobe" for product "Experience Manager Forms Add-on"
6.5.6.0
Search vendor "Adobe" for product "Experience Manager Forms Add-on" and version "6.5.6.0"
-
Affected