Impact
Adobe Experience Manager is vulnerable to a Server‑Side Request Forgery (SSRF) flaw that allows an attacker to instruct the application to send requests to arbitrary internal or external servers. The flaw can result in arbitrary code execution in the context of the current user; a low‑privileged attacker can exploit it to gain elevated privileges or take over the victim’s account. The vulnerability is network‑based, does not require user interaction, and changes the scope so that exploitation may affect the entire site.
Affected Systems
Adobe publishes the vulnerability against all versions of Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and the Cloud Service edition. All instances of these products are susceptible until a patch is applied, with no specific sub‑versions singled out.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity, while the EPSS score of under 1% suggests a low current probability of exploitation. The flaw is not listed in CISA KEV. Based on the SSRF nature, the attack path likely involves an attacker crafting a request that forces the AEM server to send a probe to an internal endpoint; this is inferred from the description that the attacker can issue unauthorized server‑side requests. Because the attacker only needs access to the network path used by AEM and no user interaction, the risk for organizations with exposed AEM instances remains high.
OpenCVE Enrichment