CVE-2024-36227
published 2024-06-13CVE-2024-36227: Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.31%
23.2th percentile
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a user to click on a specially crafted link or to submit a malicious form.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_experience_manager | <= 6.5.20 | — |
| adobe | experience_manager | < 6.5.21 | 6.5.21 |
| adobe | experience_manager | < 2024.5 | 2024.5 |
| libarchive | libarchive | >= 0 < 3.4.0-2ubuntu1.3 | 3.4.0-2ubuntu1.3 |
| libarchive | libarchive | >= 0 < 3.6.0-1ubuntu1.2 | 3.6.0-1ubuntu1.2 |
| libarchive | libarchive | >= 0 < 3.7.2-2ubuntu0.2 | 3.7.2-2ubuntu0.2 |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.8+esm3 | 3.1.2-7ubuntu2.8+esm3 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.8+esm1 | 3.1.2-11ubuntu0.16.04.8+esm1 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.7+esm1 | 3.2.2-3.1ubuntu0.7+esm1 |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libarchive vulnerabilities
osv·2024-10-16·CVSS 9.8
CVE-2022-36227 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive mishandled certain memory checks,
which could result in a NULL pointer dereference. An attacker could
potentially use this issue to cause a denial of service. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-36227)
It was discovered that libarchive mishandled certain memory operations,
which could result in an out-of-bounds memory access. An attacker could
potentially use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS.
(CVE-2024-48957, CVE-2024-48958)
GHSA
GHSA-3w29-9x4p-299p: Adobe Experience Manager versions 6
ghsa_unreviewed·2024-06-13
CVE-2024-36227 [MEDIUM] CWE-79 GHSA-3w29-9x4p-299p: Adobe Experience Manager versions 6
Adobe Experience Manager versions 6.5.20 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. This vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser session. Exploitation of this issue typically requires user interaction, such as convincing a user to click on a specially crafted link or to submit a malicious form.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-06-13
Published