CVE-2020-9733: Sensitive information disclosure possible in AEM
Published Sep 10, 2020
·Updated
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
Affected Software
6 affected components
Adobe Experience Manager<=6.2.1.20
Adobe Experience Manager>=6.3.0.0<=6.3.3.8
Adobe Experience Manager>=6.4.0.0<=6.4.8.1
Adobe Experience Manager>=6.5.0.0<=6.5.5.0
Adobe Experience Manager Forms=6.4.8.1
Adobe Experience Manager Forms=6.5.5.0
Remediation
Event History
Sep 10, 2020
CVE Published
via MITRE·04:34 PM
Data Sourced
via MITRE·04:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-9733?
CVE-2020-9733 has a high severity rating due to the potential exposure of sensitive data.
2
How do I fix CVE-2020-9733?
To mitigate CVE-2020-9733, upgrade to Adobe Experience Manager versions 6.5.5.1 or later and 6.4.8.2 or later.
3
What are the affected versions in CVE-2020-9733?
CVE-2020-9733 affects Adobe Experience Manager versions up to 6.5.5.0 and 6.4.8.1 and below.
4
What type of access can be gained through exploitation of CVE-2020-9733?
Exploitation of CVE-2020-9733 could allow an attacker to gain read-only access to sensitive data in the AEM repository.
5
What components are vulnerable according to CVE-2020-9733?
CVE-2020-9733 affects both the AEM Java servlet and Adobe Experience Manager Forms in specified versions.