First published: Tue Aug 24 2021(Updated: )
Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-28627 is classified as critical due to its potential for server-side request forgery attacks.
To fix CVE-2021-28627, upgrade Adobe Experience Manager to version 6.5.9.0 or later.
CVE-2021-28627 affects Adobe Experience Manager Cloud Service and versions 6.5.8.0 and below.
CVE-2021-28627 is a server-side request forgery vulnerability.
An attacker exploiting CVE-2021-28627 could potentially access systems that are usually blocked by the dispatcher.