CVE-2020-24444

MEDIUM

Adobe AEM Forms 6.5.6.0 and 6.4.8.2 - Blind Server-Side Request Forgery

Title source: manual
STIX 2.1

Description

AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the same network.

References (1)

Core 1
Core References

Scores

CVSS v3 5.8
EPSS 0.0208
EPSS Percentile 79.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

Details

CWE
CWE-918
Status published
Products (2)
adobe/experience_manager_forms_add-on 6.4.8.2
adobe/experience_manager_forms_add-on 6.5.6.0
Published Dec 10, 2020
Tracked Since Feb 18, 2026