Experience Manager versions 6.5.15.0 (and earlier) are affected by a Weak Cryptography for Passwords vulnerability that can lead to a security feature bypass. A low-privileged attacker can exploit this in order to decrypt a users password. The attack complexity is high since a successful exploitation requires to already have in possession this encrypted secret.
Obscuring a password with a trivial encoding does not protect the password.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Experience_manager | Adobe | * | 6.5.16.0 (excluding) |
Experience_manager_cloud_service | Adobe | * | 2023.1.0 (excluding) |