CVE-2024-41839

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*

History

12 Sep 2024, 15:58

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.1
v2 : unknown
v3 : 3.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
First Time Adobe experience Manager
Adobe
References () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - Vendor Advisory

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Las versiones 6.5.20 y anteriores de Adobe Experience Manager se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría provocar una omisión de la función de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para omitir las medidas de seguridad y afectar la integridad de la página. La explotación de este problema requiere la interacción del usuario.

23 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 12:15

Updated : 2024-09-16 13:15


NVD link : CVE-2024-41839

Mitre link : CVE-2024-41839

CVE.ORG link : CVE-2024-41839


JSON object : View

Products Affected

adobe

  • experience_manager
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation