CVE-2021-28627: Adobe Experience Manager Server-side Request Forgery could lead to Security feature bypass
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28627?
The severity of CVE-2021-28627 is classified as critical due to its potential for server-side request forgery attacks.
How do I fix CVE-2021-28627?
To fix CVE-2021-28627, upgrade Adobe Experience Manager to version 6.5.9.0 or later.
Who is affected by CVE-2021-28627?
CVE-2021-28627 affects Adobe Experience Manager Cloud Service and versions 6.5.8.0 and below.
What type of vulnerability is CVE-2021-28627?
CVE-2021-28627 is a server-side request forgery vulnerability.
What could an attacker achieve by exploiting CVE-2021-28627?
An attacker exploiting CVE-2021-28627 could potentially access systems that are usually blocked by the dispatcher.