Show plain JSON{"id": "CVE-2020-24444", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 5.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N", "authentication": "NONE", "integrityImpact": "NONE", "accessComplexity": "LOW", "availabilityImpact": "NONE", "confidentialityImpact": "PARTIAL"}, "acInsufInfo": false, "impactScore": 2.9, "baseSeverity": "MEDIUM", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV31": [{"type": "Secondary", "source": "psirt@adobe.com", "cvssData": {"scope": "CHANGED", "version": "3.1", "baseScore": 5.8, "attackVector": "NETWORK", "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N", "integrityImpact": "NONE", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "NONE", "privilegesRequired": "NONE", "confidentialityImpact": "LOW"}, "impactScore": 1.4, "exploitabilityScore": 3.9}]}, "published": "2020-12-10T06:15:13.343", "references": [{"url": "https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html", "tags": ["Vendor Advisory"], "source": "psirt@adobe.com"}, {"url": "https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html", "tags": ["Vendor Advisory"], "source": "af854a3a-2127-422b-91ae-364da2661108"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Secondary", "source": "psirt@adobe.com", "description": [{"lang": "en", "value": "CWE-918"}]}], "descriptions": [{"lang": "en", "value": "AEM Forms SP6 add-on for AEM 6.5.6.0 and Forms add-on package for AEM 6.4 Service Pack 8 Cumulative Fix Pack 2 (6.4.8.2) have a blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability could be exploited by an unauthenticated attacker to gather information about internal systems that reside on the same network."}, {"lang": "es", "value": "El add-on AEM Forms SP6 para AEM versi\u00f3n 6.5.6.0 y el paquete add-on Forms para AEM versi\u00f3n 6.4 Service Pack versi\u00f3n 8 Cumulative Fix Pack versi\u00f3n 2 (6.4.8.2), presentan una vulnerabilidad ciega de tipo Server-Side Request Forgery (SSRF). Esta vulnerabilidad podr\u00eda ser explotada por un atacante no autenticado para recopilar informaci\u00f3n sobre los sistemas internos que residen en la misma red."}], "lastModified": "2024-11-21T05:14:50.367", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:a:adobe:experience_manager_forms_add-on:6.4.8.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C42034BB-8DBA-4687-964A-1D56030DCF0E"}, {"criteria": "cpe:2.3:a:adobe:experience_manager_forms_add-on:6.5.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BC7E1A48-69DC-4114-AFB8-71670C04B866"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@adobe.com"}