First published: Wed Nov 15 2023(Updated: )
This vulnerability allows remote attackers to bypass authentication on affected installations of Adobe FrameMaker Publishing Server. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2023-44324.
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe FrameMaker |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-23-1654 has a CVSS rating of 9.8, indicating critical severity.
ZDI-23-1654 allows remote attackers to bypass authentication on affected installations without requiring authentication.
ZDI-23-1654 affects all affected installations of Adobe FrameMaker Publishing Server.
No, authentication is not required to exploit ZDI-23-1654.
Mitigation steps for ZDI-23-1654 include applying available updates from Adobe and restricting access to the affected service.