First published: Fri Nov 17 2023(Updated: )
Adobe FrameMaker Publishing Server versions 2022 and earlier are affected by an Improper Authentication vulnerability that could result in a Security feature bypass. An unauthenticated attacker can abuse this vulnerability to access the API and leak default admin's password. Exploitation of this issue does not require user interaction.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Adobe FrameMaker Publishing Server | <2022 | |
Adobe FrameMaker Publishing Server | =2022 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe FrameMaker vulnerability is CVE-2023-44324.
The title of this Adobe FrameMaker vulnerability is ZDI-CAN-21344: Adobe FrameMaker Publishing Server Authentication Bypass Vulnerability.
The severity level of CVE-2023-44324 is critical with a severity value of 9.8.
Adobe FrameMaker versions 2022 and earlier are affected by this vulnerability.
An unauthenticated attacker can abuse this vulnerability to access the API and leak the default admin's password.