Get a Pentest and security assessment of your IT network.

News

Undocumented authentication bypass issue in AEM Package Manager [Blog updated]

Adobe Experience Manager (AEM) is a content management solution for building digital customer experiences. Security researchers and Detectify Crowdsource members Ai Ho (@j3ssiejjj) and Bao Bui (@Jok3rDb), discovered the issue. The vulnerability occurs when default security controls are manually turned off on the Package Manager content tree, by default /etc/packages. This issue allows an unauthorized user to view and download packages. The vulnerability does not require a CVE from Adobe because AEM has the necessary security controls enabled by default to help protect customers.”]

Source: https://labs.detectify.com/2021/06/28/aem-crx-bypass-0day-control-over-some-enterprise-aem-crx-package-manager/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin