Bulletin ID
Security updates available for Adobe Experience Manager | APSB18-23
Bulletin ID |
Date Published |
Priority |
---|---|---|
APSB18-23 |
July 10, 2018 |
2 |
Adobe has released security updates for Adobe Experience Manager. These updates resolve three Server-Side Request Forgery (SSRF) vulnerabilities rated Important that could result in sensitive information disclosure.
Product |
Version |
Platform |
---|---|---|
Adobe Experience Manager |
6.4 6.3 6.2 6.1 6.0 |
All |
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
Product |
Version |
Platform |
Priority |
Availability |
---|---|---|---|---|
Adobe Experience Manager |
6.4 |
All |
2 |
|
6.3 |
All |
2 |
||
6.2 |
All |
2 |
||
6.1 |
All |
2 |
||
6.0 |
All |
2 |
Please contact Adobe customer care for assistance with earlier AEM versions.
Vulnerability Category |
Vulnerability Impact |
Severity |
CVE Numbers |
Affected Version |
Download Package |
---|---|---|---|---|---|
Server-Side Request Forgery |
Sensitive Information disclosure |
Important |
CVE-2018-5004 |
AEM 6.2 AEM 6.3 |
|
Server-Side Request Forgery |
Sensitive Information Disclosure |
Important |
CVE-2018-5006 |
AEM 6.4 and earlier |
|
Server-Side Request Forgery
|
Sensitive Information disclosure
|
Important
|
CVE-2018-12809
|
AEM 6.4 and earlier
|
The packages listed in the table above are the minimum fix packs to address the listed vulnerability. For the latest versions, please see the release notes links referenced above.
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:
Mikhail Egorov @0ang3el (CVE-2018-5006, CVE-2018-12809)
Sign in to your account