CVE-2017-11296: XSS
Published Dec 9, 2017
·Updated
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.
Affected Software
4 affected components
Adobe Experience Manager=6.0.0
Adobe Experience Manager=6.1.0
Adobe Experience Manager=6.2.0
Adobe Experience Manager=6.3.0
Event History
Dec 9, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-11296?
The severity of CVE-2017-11296 is classified as moderate due to its potential for cross-site scripting attacks.
2
What versions of Adobe Experience Manager are affected by CVE-2017-11296?
CVE-2017-11296 affects Adobe Experience Manager versions 6.0, 6.1, 6.2, and 6.3.
3
How do I fix CVE-2017-11296?
To fix CVE-2017-11296, upgrade your Adobe Experience Manager to the latest patched version provided by Adobe.
4
What type of vulnerability is CVE-2017-11296?
CVE-2017-11296 is a cross-site scripting (XSS) vulnerability found in Apache Sling Servlets.
5
Is there a workaround for CVE-2017-11296?
There are no specific workarounds for CVE-2017-11296; the recommended action is to apply the available updates.