First published: Thu Dec 15 2016(Updated: )
Adobe Experience Manager Forms versions 6.2 and earlier, LiveCycle 11.0.1, LiveCycle 10.0.4 have an input validation issue in the AACComponent that could be used in cross-site scripting attacks.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | =6.0.0 | |
Adobe Experience Manager | =6.1.0 | |
Adobe Experience Manager | =6.2.0 | |
Adobe LiveCycle | =10.0.4 | |
Adobe LiveCycle | =11.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6933 has a medium severity rating due to its potential for exploitation in cross-site scripting attacks.
To remediate CVE-2016-6933, update Adobe Experience Manager Forms to a version later than 6.2 and LiveCycle to a later version than 11.0.1.
CVE-2016-6933 can potentially allow attackers to execute malicious scripts in the context of a user's browser session.
CVE-2016-6933 affects Adobe Experience Manager Forms versions 6.2 and earlier, and LiveCycle versions 11.0.1 and 10.0.4.
CVE-2016-6933 is not uncommon as input validation issues are frequently found in web applications, highlighting the need for proper security measures.