First published: Tue Aug 24 2021(Updated: )
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by an Improper Authorization vulnerability allowing users to create nodes under a location. An unauthenticated attacker could leverage this vulnerability to cause an application denial-of-service. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28626.
The severity of CVE-2021-28626 is high with a CVSS score of 7.5.
The affected software for CVE-2021-28626 is Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below).
CVE-2021-28626 is an Improper Authorization vulnerability in Adobe Experience Manager Cloud Service offering and versions 6.5.8.0 (and below) that allows unauthenticated users to create nodes under a location, potentially leading to application denial-of-service.
An unauthenticated attacker could leverage CVE-2021-28626 to cause an application denial-of-service.