CVE-2021-40745: Adobe Campaign Path Traversal Leads to Information Exposure
Adobe Campaign version 21.2.1 (and earlier) is affected by a Path Traversal vulnerability that could lead to reading arbitrary server files. By leveraging an exposed XML file, an unauthenticated attacker can enumerate other files on the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-40745?
CVE-2021-40745 is a Path Traversal vulnerability in Adobe Campaign version 21.2.1 (and earlier) that allows an unauthenticated attacker to read arbitrary server files.
How severe is CVE-2021-40745?
CVE-2021-40745 has a severity rating of 7.5 (high).
How does CVE-2021-40745 affect Adobe Campaign?
CVE-2021-40745 affects Adobe Campaign version 21.2.1 (and earlier), allowing an unauthenticated attacker to read arbitrary server files.
How can an attacker exploit CVE-2021-40745?
An attacker can exploit CVE-2021-40745 by leveraging an exposed XML file to enumerate other files on the server.
Is Linux or Windows affected by CVE-2021-40745?
No, Linux and Windows are not affected by CVE-2021-40745.