First published: Wed Nov 17 2021(Updated: )
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Campaign | <=21.2.1 | |
Linux Linux kernel | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40745 is a Path Traversal vulnerability in Adobe Campaign version 21.2.1 (and earlier) that allows an unauthenticated attacker to read arbitrary server files.
CVE-2021-40745 has a severity rating of 7.5 (high).
CVE-2021-40745 affects Adobe Campaign version 21.2.1 (and earlier), allowing an unauthenticated attacker to read arbitrary server files.
An attacker can exploit CVE-2021-40745 by leveraging an exposed XML file to enumerate other files on the server.
No, Linux and Windows are not affected by CVE-2021-40745.