An AEM java servlet in AEM versions 6.5.5.0 (and below) and 6.4.8.1 (and below) executes with the permissions of a high privileged service user. If exploited, this could lead to read-only access to sensitive data in an AEM repository.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb20-56.html | patch vendor advisory |