First published: Sat Dec 09 2017(Updated: )
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | =6.0.0 | |
Adobe Experience Manager | =6.1.0 | |
Adobe Experience Manager | =6.2.0 | |
Adobe Experience Manager | =6.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3109 is rated as medium severity due to its potential impact on application security.
To fix CVE-2017-3109, update Adobe Experience Manager to version 6.3 or later, as this version contains the necessary security patches.
The main issue caused by CVE-2017-3109 is a reflected cross-site scripting vulnerability that can allow attackers to execute arbitrary scripts in the context of the user's session.
CVE-2017-3109 affects Adobe Experience Manager versions 6.0, 6.1, 6.2, and 6.3.
Yes, CVE-2017-3109 can be exploited remotely via specially crafted requests to the affected system.