CVE Vulnerabilities

CVE-2020-9733

Improper Privilege Management

Published: Sep 10, 2020 | Modified: Sep 14, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Experience_manager Adobe * 6.2.1.20 (including)
Experience_manager Adobe 6.3.0.0 (including) 6.3.3.8 (including)
Experience_manager Adobe 6.4.0.0 (including) 6.4.8.1 (including)
Experience_manager Adobe 6.5.0.0 (including) 6.5.5.0 (including)
Experience_manager_forms Adobe 6.4.8.1 (including) 6.4.8.1 (including)
Experience_manager_forms Adobe 6.5.5.0 (including) 6.5.5.0 (including)

Potential Mitigations

References