Impact
Adobe Experience Manager is vulnerable to Improper Input Validation that can allow a security feature bypass, giving a low‑privileged attacker unauthorized limited write access. The weakness enables an attacker to supply malicious input that is not properly validated, leading to a bypass of normal security controls. Although the impact is contained to write permissions, it permits an attacker to alter or add content within the scope of their limited privileges.
Affected Systems
The affected vendors and products are Adobe Experience Manager versions 6.5, Adobe Experience Manager 6.5 LTS, and Adobe Experience Manager as a Cloud Service. No further version details are provided beyond the 6.5 line.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity. Exploitation requires user interaction with a maliciously crafted URL or compromised web page, so an attacker must entice a victim to click or visit a link. EPSS information is not available and the vulnerability is not listed in the CISA KEV catalog, which suggests current exploitation risk is low but not negligible. The attack vector is mainly web‑based user interaction; no remote code execution or automatic exploitation is described.
OpenCVE Enrichment