Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
85Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actcvss 8.6epss 77%
from disclosure to weapon189 days
Published on NVDAug 5
1st PoC+189d
VulnCheck+7d
exploitation probability
77%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short
Adobe Experience Manager has a flaw that allows attackers to read sensitive files from the server's file system by sending specially crafted XML requests. No user interaction is needed for the attack to work.
Technical detail
An XXE (XML External Entity) vulnerability in Adobe Experience Manager 6.5.23 and earlier allows unauthenticated attackers to read arbitrary files from the server's filesystem through malicious XML input. The vulnerability requires no user interaction and results in unauthorized information disclosure with elevated scope impact.
Summary generated and translated by AI from the official description.
Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Affected products
Adobe · Adobe Experience Managerpublic PoCs found — 1
vulncheckvulncheck.com/xdb/ceefb245d3d1unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.