First published: Mon Sep 27 2021(Updated: )
Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Experience Manager | <=6.5.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40713 is categorized as a critical vulnerability due to potential man-in-the-middle attacks.
To remediate CVE-2021-40713, upgrade Adobe Experience Manager to version 6.5.9.1 or later.
CVE-2021-40713 is an improper certificate validation vulnerability affecting Adobe Experience Manager.
Adobe Experience Manager versions up to and including 6.5.9.0 are affected by CVE-2021-40713.
CVE-2021-40713 allows an attacker to exploit a man-in-the-middle position during certificate establishment.