CVE-2020-9733
- EPSS 0.49%
- Veröffentlicht 10.09.2020 17:15:36
- Zuletzt bearbeitet 21.11.2024 05:41:10
An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
- EPSS 0.7%
- Veröffentlicht 10.09.2020 17:15:35
- Zuletzt bearbeitet 21.11.2024 05:41:10
The AEM Forms add-on for versions 6.5.5.0 (and below) and 6.4.8.2 (and below) are affected by a stored XSS vulnerability that allows users with 'Author' privileges to store malicious scripts in fields associated with the Sites component. These script...
CVE-2020-9648
- EPSS 14.03%
- Veröffentlicht 12.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:41:01
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9651
- EPSS 14.03%
- Veröffentlicht 12.06.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 05:41:02
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (reflected) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9643
- EPSS 1.09%
- Veröffentlicht 12.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:41:01
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9644
- EPSS 5.97%
- Veröffentlicht 12.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:41:01
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (stored) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-9645
- EPSS 1.09%
- Veröffentlicht 12.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:41:01
Adobe Experience Manager versions 6.5 and earlier have a blind server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-9647
- EPSS 14.03%
- Veröffentlicht 12.06.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:41:01
Adobe Experience Manager versions 6.5 and earlier have a cross-site scripting (dom-based) vulnerability. Successful exploitation could lead to arbitrary javascript execution in the browser.
CVE-2020-3769
- EPSS 1.09%
- Veröffentlicht 25.03.2020 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:31:42
Adobe Experience Manager versions 6.5 and earlier have a server-side request forgery (ssrf) vulnerability. Successful exploitation could lead to sensitive information disclosure.
CVE-2020-3741
- EPSS 2.18%
- Veröffentlicht 13.02.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:31:40
Adobe Experience Manager versions 6.5, and 6.4 have an uncontrolled resource consumption vulnerability. Successful exploitation could lead to denial-of-service.