漏洞描述
Adobe Experience Manager 6.5, 6.4, 6.3 and 6.2 are susceptible to XML external entity injection. An attacker can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
speakerdeck.comhttps://speakerdeck.com/0ang3el/a-hackers-perspective-on-aem-applications-security?slide=13↗github.comhttps://github.com/0ang3el/aem-hacker/blob/master/aem_hacker.py↗cve.mitre.orghttps://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-8086↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-8086↗helpx.adobe.comhttps://helpx.adobe.com/security/products/experience-manager/apsb19-48.html↗