CVE-2022-42351
AEM Incorrect Authorization Security feature bypass
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Adobe Experience Manager version 6.5.14 (and earlier) is affected by an Incorrect Authorization vulnerability that could result in a security feature bypass. A low-privileged attacker could leverage this vulnerability to disclose low level confidentiality information. Exploitation of this issue does not require user interaction.
Adobe Experience Manager versión 6.5.14 (y anteriores) se ve afectado por una vulnerabilidad de autorización incorrecta que podría provocar la omisión de una característica de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para revelar información confidencial de bajo nivel. La explotación de este problema no requiere la interacción del usuario.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2022-10-03 CVE Reserved
- 2022-12-16 CVE Published
- 2024-07-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb22-59.html | 2022-12-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Experience Manager Search vendor "Adobe" for product "Experience Manager" | < 6.5.15.0 Search vendor "Adobe" for product "Experience Manager" and version " < 6.5.15.0" | - |
Affected
| ||||||
Adobe Search vendor "Adobe" | Experience Manager Cloud Service Search vendor "Adobe" for product "Experience Manager Cloud Service" | < 2022.10.0 Search vendor "Adobe" for product "Experience Manager Cloud Service" and version " < 2022.10.0" | - |
Affected
|