CVE-2019-16468Injection in Adobe Experience Manager

Severity
7.5HIGHNVD
EPSS
4.2%
top 11.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 15
Latest updateMay 24

Description

Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an user interface injection vulnerability. Successful exploitation could lead to sensitive information disclosure.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDadobe/experience_manager6.36.3.3.7+2
CVEListV5adobe/adobe_experience_manager6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 versions

Patches

🔴Vulnerability Details

1
GHSA
GHSA-j26m-mhw3-8vc7: Adobe Experience Manager versions 62022-05-24
CVE-2019-16468 — Injection in Adobe Experience Manager | cvebase