Impact
Adobe Experience Manager Forms JEE is vulnerable to server‑side request forgery that allows an attacker with high privileges to instruct the server to send requests to arbitrary internal resources, potentially accessing data or services that should be isolated. This flaw, marked as having changed scope, can thus affect a broader set of system components.
Affected Systems
Adobe Experience Manager 6.5 Forms JEE and Adobe Experience Manager 6.5 LTS Forms JEE are affected. No specific version information is listed, so any deployment of these products could be vulnerable unless the latest Adobe patch is applied.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity risk, and the EPSS score is not available, indicating that exploitation frequency is not quantified but the flaw remains significant. The issue does not require user interaction, making automated exploitation possible, and it is not listed in the CISA KEV catalog. Attackers with sufficient privileges can leverage the SSRF to reach internal services, potentially escalating privileges.
OpenCVE Enrichment