Impact
The vulnerability in Adobe Experience Manager is a DOM-based Cross‑Site Scripting flaw that allows an attacker to inject and execute malicious JavaScript within the context of a victim’s browser. This can enable session hijacking, credential theft, or other malicious actions performed in the user’s context. The weakness aligns with CWE‑79. Exploitation requires the victim to click on a crafted web page or otherwise interact with malicious content, and it requires manipulation of the DOM environment to run attacker‑supplied code.
Affected Systems
Adobe Experience Manager 6.5, 6.5 LTS, and the Adobe Experience Manager as a Cloud Service editions are impacted. The CNA data does not provide finer version granularity beyond the product families mentioned.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, but the lack of an EPSS score and absence from the CISA KEV catalog suggest that exploitation is not currently widespread. The attack vector is inferred to be a web page that the victim must visit, and the scope change noted in the CVSS calculation implies that the vulnerability may affect resources or privileges beyond the initially targeted one, potentially increasing the overall impact of a successful exploitation. Non‑interaction of the vulnerability is required; user engagement is mandatory to trigger the DOM manipulation. The moderate CVSS score combined with the necessity for user interaction suggests a tangible but contained risk if the affected system is exposed to public or semi‑public web traffic.
OpenCVE Enrichment