CVE-2024-41839

Adobe Experience Manager versions 6.5.20 and earlier are affected by an Improper Input Validation vulnerability that could lead to a security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and affect the integrity of the page. Exploitation of this issue requires user interaction.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*

History

21 Nov 2024, 09:33

Type Values Removed Values Added
References () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - Vendor Advisory () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - Vendor Advisory

12 Sep 2024, 15:58

Type Values Removed Values Added
First Time Adobe
Adobe experience Manager
CPE cpe:2.3:a:adobe:experience_manager:*:*:*:*:aem_cloud_service:*:*:*
cpe:2.3:a:adobe:experience_manager:*:*:*:*:-:*:*:*
References () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - () https://helpx.adobe.com/security/products/experience-manager/apsb24-28.html - Vendor Advisory
CVSS v2 : unknown
v3 : 4.1
v2 : unknown
v3 : 3.5
CWE NVD-CWE-noinfo

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Las versiones 6.5.20 y anteriores de Adobe Experience Manager se ven afectadas por una vulnerabilidad de validación de entrada incorrecta que podría provocar una omisión de la función de seguridad. Un atacante con pocos privilegios podría aprovechar esta vulnerabilidad para omitir las medidas de seguridad y afectar la integridad de la página. La explotación de este problema requiere la interacción del usuario.

23 Jul 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 12:15

Updated : 2024-11-21 09:33


NVD link : CVE-2024-41839

Mitre link : CVE-2024-41839

CVE.ORG link : CVE-2024-41839


JSON object : View

Products Affected

adobe

  • experience_manager
CWE
CWE-20

Improper Input Validation

NVD-CWE-noinfo