Adobe Experience Manager (AEM) is a content management solution for building digital customer experiences. Security researchers and Detectify Crowdsource members Ai Ho (@j3ssiejjj) and Bao Bui (@Jok3rDb), discovered the issue. The vulnerability occurs when default security controls are manually turned off on the Package Manager content tree, by default /etc/packages. This issue allows an unauthorized user to view and download packages. The vulnerability does not require a CVE from Adobe because AEM has the necessary security controls enabled by default to help protect customers.”]

