Adobe Security Bulletin

Security updates available for Adobe Experience Manager | APSB18-26

Bulletin ID

Date Published

Priority

APSB18-26

August 14, 2018

2

Summary

Adobe has released security updates for Adobe Experience Manager. These updates resolve cross-site scripting vulnerabilities rated Moderate that could result in sensitive information disclosure and an input validation bypass vulnerability rated Moderate which could allow unauthorized information modification.

Affected product versions

Product

Version

Platform

Adobe Experience Manager

6.4

6.3

6.2

6.1

6.0

All

Solution

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:

Product

Version

Platform

Priority

Availability

 

 

 

Adobe Experience Manager

6.4

All

2

Releases and Updates

6.3

All

2

Releases and Updates

6.2

All

2

Releases and Updates

6.1

All

2

Releases and Updates

6.0

All

2

Releases and Updates

Please contact Adobe customer care for assistance with earlier AEM versions.

Vulnerability details

Vulnerability Category

Vulnerability Impact

Severity

CVE Numbers

Affected Version

Download Package

Reflected Cross-site Scripting

Sensitive Information disclosure

Moderate

CVE-2018-12806

AEM 6.1

AEM 6.2

Input Validation Bypass

Unauthorized Information Modification

Moderate

CVE-2018-12807

AEM 6.3and earlier

 

 

Cross-site Scripting

 

 

 

 

Sensitive Information disclosure

 

 

 

 

Moderate

 

 

 

 

CVE-2018-5005

 

 

 

AEM 6.2

AEM 6.3

AEM6.4

Note:

The packages listed in the table above are the minimum fix packs to address the listed vulnerability.  For the latest versions, please see the release notes links referenced above.

Acknowledgments

Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers:

  • Nagamarimuthu of Cognizant Technology Solutions - Enterprise Risk & Security Solutions (CVE-2018-12806)

  • Chia Min Jun Lennon (CVE-2018-12807)

Adobe logo

Sign in to your account