Improper file type validation in Adobe Experience Manager - CVE-2017-3108

 

Improper file type validation in Adobe Experience Manager - CVE-2017-3108

Published: August 8, 2017


Vulnerability identifier: #VU7698
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-3108
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to file type validation error when uploading files. A remote attacker can bypass validation process and upload malicious file on vulnerable system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.

Affected software

Adobe Experience Manager

How to mitigate CVE-2017-3108



External References

Related Security Bulletins