CVE-2021-21083: Adobe Experience Manager broken access control in DSRPReindexServlet could lead to denial-of-service
AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are affected by an Improper Access Control vulnerability. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service in the context of the current user.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-21083.
What is the severity of CVE-2021-21083?
The severity of CVE-2021-21083 is high, with a severity value of 7.5.
Which versions of Adobe Experience Manager are affected by CVE-2021-21083?
Adobe Experience Manager versions 6.5.7.0 (and below), 6.4.8.3 (and below), and 6.3.3.8 (and below) are affected by CVE-2021-21083.
What is the affected component for CVE-2021-21083?
The affected component for CVE-2021-21083 is Adobe Experience Manager Cloud Service.
How can an unauthenticated attacker leverage CVE-2021-21083?
An unauthenticated attacker can leverage CVE-2021-21083 to cause an application denial-of-service in the context of the affected component.