Adobe Experience Manager version 6.5.9.0 (and earlier) is affected by a improper certificate validation vulnerability in the cold storage component. If an attacker can achieve a man in the middle when the cold server establishes a new certificate, they would be able to harvest sensitive information.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://helpx.adobe.com/security/products/experience-manager/apsb21-82.html | patch vendor advisory |