Impact
Adobe Experience Manager is vulnerable to an improper limitation of a pathname to a restricted directory, a path traversal flaw that allows arbitrary file system read. It permits an attacker to access sensitive files and directories outside the intended scope. The vulnerability can be exploited remotely without any user interaction and changes the security scope of the affected services. The flaw is identified as CWE‑22.
Affected Systems
Adobe Experience Manager 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service are impacted.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via crafted HTTP requests that exploit the path handling logic to traverse beyond the intended directory, bypassing directory restrictions.
OpenCVE Enrichment