Record summary

CVE-2019-8086 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List6.5affected
6.4affected
6.3affected
6.2affected

Nuclei templates

1
ProjectDiscoveryHIGHAdobe Experience Manager - XML External Entity InjectionCVSS 7.5

Adobe Experience Manager 6.5, 6.4, 6.3 and 6.2 are susceptible to XML external entity injection. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability can lead to unauthorized access to sensitive information, server-side request forgery, and potential remote code execution.

Remediation

Apply the necessary security patches provided by Adobe to mitigate the vulnerability. Additionally, ensure that the server is properly configured to restrict access to sensitive files and prevent XXE attacks.

WeaknessesCWE-611
AuthorsDhiyaneshDk
Template tagscvecve2019aemadobevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:adobe:experience_manager:6.2:*:*:*:*:*:*:*
Shodan: http.title:"AEM Sign In"
Shodan: http.component:"Adobe Experience Manager"
Shodan: http.component:"adobe experience manager"
Shodan: http.title:"aem sign in"
Shodan: cpe:"cpe:2.3:a:adobe:experience_manager"
FOFA: title="aem sign in"
Google: intitle:"aem sign in"

Source: ProjectDiscovery

References

2