CVE-2024-26063

MEDIUM

Adobe Experience Manager < 6.5.20.0 and < 2024.3.0 - Information Exposure and Security Feature Bypass

Title source: llm
STIX 2.1

Description

Adobe Experience Manager versions 6.5.19 and earlier are affected by an Information Exposure vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to gain unauthorized access to sensitive information, potentially bypassing security measures. Exploitation of this issue does not require user interaction.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0026
EPSS Percentile 49.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-200
Status published
Products (2)
adobe/experience_manager < 2024.3.0
adobe/experience_manager < 6.5.20.0
Published Mar 18, 2024
Tracked Since Feb 18, 2026