Improper input validation in Adobe Campaign - CVE-2017-2989

 

Improper input validation in Adobe Campaign - CVE-2017-2989

Published: April 11, 2017 / Updated: April 11, 2017


Vulnerability identifier: #VU6194
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2989
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to read, write or delete data on the target system.

The weakness exists due to improper input validation. A remote attacker can create a specially crafted file, trick the victim into opening it and read, write or delete data from the Campaign database.

Successful exploitation of the vulnerability results in compromise vulnerable system.

Affected software

Adobe Campaign

How to mitigate CVE-2017-2989

Update to version 6.11 Build 8795.


External References

Related Security Bulletins