CVE-2021-40722: AEM Forms Improper Restriction of XML External Entity Reference
Published Jan 13, 2022
·Updated
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
Affected Software
2 affected components
Adobe Experience Manager<=6.5.10.0
Adobe Experience Manager Cloud Service
Event History
Jan 13, 2022
CVE Published
via MITRE·08:27 PM
Data Sourced
via MITRE·08:27 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this AEM Forms Cloud Service vulnerability?
The vulnerability ID for this AEM Forms Cloud Service vulnerability is CVE-2021-40722.
2
What is the severity of CVE-2021-40722?
The severity of CVE-2021-40722 is critical with a score of 9.8.
3
Which software versions are affected by CVE-2021-40722?
Version 6.5.10.0 (and below) of Adobe Experience Manager and Adobe Experience Manager Cloud Service are affected by CVE-2021-40722.
4
What is the impact of the XML External Entity (XXE) injection vulnerability?
The XML External Entity (XXE) injection vulnerability can be abused by an attacker to achieve Remote Code Execution (RCE).
5
How can I fix the CVE-2021-40722 vulnerability?
To fix the CVE-2021-40722 vulnerability, it is recommended to update Adobe Experience Manager to a version that is not affected by this vulnerability.