First published: Wed Feb 10 2016(Updated: )
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Sling | ||
Adobe Experience Manager | =5.6.1 | |
Adobe Experience Manager | =6.0.0 | |
Adobe Experience Manager | =6.1.0 | |
macOS Yosemite | ||
Linux Kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0956 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To address CVE-2016-0956, it is recommended to upgrade to a patched version of Apache Sling that resolves this vulnerability.
CVE-2016-0956 affects Apache Sling 2.3.6 and Adobe Experience Manager versions 5.6.1, 6.0.0, and 6.1.0.
CVE-2016-0956 is an information disclosure vulnerability that allows remote attackers to obtain sensitive information.
CVE-2016-0956 remains exploitable in the affected software versions unless mitigated with appropriate updates.