Information disclosure in Adobe Experience Manager Forms



Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2017-3067
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
Adobe Experience Manager Forms
Client/Desktop applications / Multimedia software

Vendor Adobe

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU6438

Risk: Low

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2017-3067

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

Exploit availability: No

Description

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to abuse of the pre-population service in AEM Forms. A remote attacker can gain access to file paths and protocols used to pre-fill a form and view arbitrary files.

Successful exploitation of the vulnerability results on information disclosure.

Mitigation

Update to version 6.1 SP2 CFP8 or 6.2 SP1 CFP3.

Vulnerable software versions

Adobe Experience Manager Forms: 6.0 - 6.2

CPE2.3 External links

https://helpx.adobe.com/security/products/aem-forms/apsb17-16.html


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###