AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: adobe

Published: 2021-12-14T00:00:00

Updated: 2022-01-13T20:27:18

Reserved: 2021-09-08T00:00:00


Link: CVE-2021-40722

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-13T21:15:07.897

Modified: 2022-01-19T15:13:22.820


Link: CVE-2021-40722

JSON object: View

cve-icon Redhat Information

No data.

CWE