Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb21-82.html | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: adobe
Published: 2021-09-14T00:00:00
Updated: 2021-09-27T15:43:07
Reserved: 2021-09-08T00:00:00
Link: CVE-2021-40713
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-09-27T16:15:10.727
Modified: 2021-10-01T13:19:05.413
Link: CVE-2021-40713
JSON object: View
Redhat Information
No data.
CWE