CVE-2024-43729: Adobe Experience Manager | Improper Authorization (CWE-285)
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a high impact on integrity. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43729?
CVE-2024-43729 has a medium severity rating, which indicates a notable impact on integrity due to improper authorization.
How do I fix CVE-2024-43729?
To fix CVE-2024-43729, upgrade Adobe Experience Manager to version 6.5.22 or later, or to version 2024.11.0 or later for AEM Cloud Service.
Who is affected by CVE-2024-43729?
CVE-2024-43729 affects Adobe Experience Manager versions 6.5.21 and earlier, as well as the AEM Cloud Service versions up to 2024.10.0.
What type of vulnerability is CVE-2024-43729?
CVE-2024-43729 is categorized as an Improper Authorization vulnerability which could allow a low-privileged attacker to bypass certain security measures.
What are the potential impacts of CVE-2024-43729?
Exploitation of CVE-2024-43729 can lead to high impact on the integrity of the affected Adobe Experience Manager instances.