Information disclosure in Backup functionality in Adobe Experience Manager - CVE-2016-4253

 

Information disclosure in Backup functionality in Adobe Experience Manager - CVE-2016-4253

Published: August 9, 2016


Vulnerability identifier: #VU269
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4253
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to unknown error in Backup functionality. A remote attacker can get access to potentially sensitive data.

Successful exploitation of this vulnerability will allow an attacker to gain unauthorized access to potentially sensitive information.


Affected software

Adobe Experience Manager

How to mitigate CVE-2016-4253

The vendor has issued fixes to address this vulnerability:

Hotfix 10870 for 6.2
Hotfix 10870 for 6.1
Hotfix 10870 for 6.0
Hotfix 10870 for 5.6.1



External References

Related Security Bulletins