CVE-2021-40713: Adobe Experience Manager Improper Certificate Validation Could Lead to Man In The Middle Attack
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-40713?
CVE-2021-40713 is categorized as a critical vulnerability due to potential man-in-the-middle attacks.
How do I fix CVE-2021-40713?
To remediate CVE-2021-40713, upgrade Adobe Experience Manager to version 6.5.9.1 or later.
What type of vulnerability is CVE-2021-40713?
CVE-2021-40713 is an improper certificate validation vulnerability affecting Adobe Experience Manager.
Who is affected by CVE-2021-40713?
Adobe Experience Manager versions up to and including 6.5.9.0 are affected by CVE-2021-40713.
What attack vector does CVE-2021-40713 expose?
CVE-2021-40713 allows an attacker to exploit a man-in-the-middle position during certificate establishment.