CVE-2024-41849

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. An low-privileged attacker could leverage this vulnerability to slightly affect the integrity of the page. Exploitation of this issue requires user interaction and scope is changed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*

History

26 Aug 2024, 14:37

Type Values Removed Values Added
First Time Adobe experience Manager
Adobe
CWE NVD-CWE-noinfo
References () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - Vendor Advisory
Summary
  • (es) Las versiones 6.5.20 y anteriores de Adobe Experience Manager se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría provocar una omisión de la función de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para afectar levemente la integridad de la página. La explotación de este problema requiere la interacción del usuario y se cambia el alcance.
CPE cpe:2.3:a:adobe:experience_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*

23 Aug 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-23 17:15

Updated : 2024-08-26 14:37


NVD link : CVE-2024-41849

Mitre link : CVE-2024-41849

CVE.ORG link : CVE-2024-41849


JSON object : View

Products Affected

adobe

  • experience_manager
CWE
NVD-CWE-noinfo CWE-20

Improper Input Validation