← volver
CVE-2021-40722criticalCWE-611

AEM Forms Improper Restriction of XML External Entity Reference

28Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 9.8epss 3.3%
probabilidad de explotación
3.3%top 12% de las CVE
explotación observada
noninguna fuente lo reporta
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
Adobe · Experience Manager