Server-side Request Forgery in Adobe Experience Manager Cloud Service and versions 6.5.8.0 and below: Unauthorized Access to Blocked Systems

Server-side Request Forgery in Adobe Experience Manager Cloud Service and versions 6.5.8.0 and below: Unauthorized Access to Blocked Systems

CVE-2021-28627 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Adobe Experience Manager Cloud Service offering, as well as versions 6.5.8.0 (and below) is affected by a Server-side Request Forgery. An authenticated attacker could leverage this vulnerability to contact systems blocked by the dispatcher. Exploitation of this issue does not require user interaction.

Learn more about our Cis Benchmark Audit For Server Software.