CVE-2016-0957
Adobe AEM Dispatcher <4.15 - Rules Bypass
Record summary
CVE-2016-0957 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHAdobe AEM Dispatcher <4.15 - Rules BypassCVSS 7.5
Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.
Impact
The vulnerability allows attackers to bypass security rules and potentially gain unauthorized access to sensitive information or perform malicious actions.
Remediation
Upgrade to Adobe AEM Dispatcher version 4.15 or higher to fix the vulnerability.
Source: ProjectDiscovery