First published: Thu Dec 15 2016(Updated: )
Adobe Experience Manager versions 6.2 and earlier have an input validation issue in the WCMDebug filter that could be used in cross-site scripting attacks.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-7882 is rated as a critical vulnerability due to its potential to allow cross-site scripting attacks.
To fix CVE-2016-7882, upgrade Adobe Experience Manager to version 6.3 or later.
CVE-2016-7882 affects Adobe Experience Manager versions 6.2 and earlier.
Yes, due to its cross-site scripting nature, CVE-2016-7882 could potentially lead to unauthorized data access.
Mitigation steps are limited; the best approach is to upgrade to the latest version of Adobe Experience Manager.