First published: Fri Oct 25 2019(Updated: )
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitive information disclosure.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | =6.2 | |
Adobe Experience Manager | =6.3 | |
Adobe Experience Manager | =6.4 | |
Adobe Experience Manager | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-8086 is classified as a critical vulnerability due to its potential for sensitive information disclosure.
To fix CVE-2019-8086, update Adobe Experience Manager to the latest version as recommended by Adobe.
Adobe Experience Manager versions 6.2, 6.3, 6.4, and 6.5 are all affected by CVE-2019-8086.
CVE-2019-8086 can be exploited through XML External Entity (XXE) injection attacks.
If CVE-2019-8086 is successfully exploited, it could lead to the disclosure of sensitive information.