Server-side request forgery in Adobe Experience Manager - CVE-2018-5006

 

Server-side request forgery in Adobe Experience Manager - CVE-2018-5006

Published: July 10, 2018


Vulnerability identifier: #VU13628
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5006
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform SSRF attack.

The weakness exists due to unspecified error. A remote attacker can perform SSRF attack to bypass network access controls, perform unauthorized connections to local resources and gain access to sensitive information.

Affected software

Adobe Experience Manager

How to mitigate CVE-2018-5006

Install update from vendor's website.


External References

Related Security Bulletins