Impact
The vulnerability is a Server‑Side Request Forgery that lets a low‑privileged attacker send requests from the server to internal addresses. By abusing this flaw the attacker can access internal resources, read or modify sensitive data, and potentially gain elevated privileges on the system. The attack does not require user interaction and the affected component can change the scope of the compromise.
Affected Systems
Adobe Experience Manager Forms JEE, including AEM 6.5 Forms JEE and AEM 6.5 LTS Forms JEE. No specific patch versions are listed, but any instance of these products is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.6 indicates a critical severity, and the EPSS score is not available, so specific exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the SSRF by sending crafted requests to internal hosts; once the request is made, the attacker can read responses and potentially manipulate resources until privilege escalation occurs.
OpenCVE Enrichment