Details of RCE Bug in Adobe Experience Manager Revealed
#1
Information 
Quote:Details of an Adobe zero-day bug found in its content-management solution Adobe Experience Manager (AEM), which affected customers ranging from Mastercard, LinkedIn and PlayStation, were revealed Monday.
 
The bug, patched in May, allowed hackers to bypass authentication protection and execute code remotely on vulnerable AEM installs.
 
Researchers in the ethical-hacking community Detectify Crowdsource identified the flaw in the CRX Package Manager component of Adobe’s AEM. AEM is an enterprise-class tool for creating and managing websites, mobile apps and online forums.

“This bug allows attackers to bypass authentication and gain access to CRX Package Manager,” researchers wrote in a blog post about the vulnerability published Monday. “Packages enable the importing and exporting of repository content, and the Package Manager can be used for configuring, building, downloading, installing and deleting packages on local AEM installations.”
 
Detectify Crowdsource members, identified as Ai Ho and Bao Bui, first discovered the vulnerability in December 2020 in an instance of AEM used by Sony Interactive Entertainment’s PlayStation subsidiary. Three months later, the AEM CRX bypass was also identified within multiple subdomains used by Mastercard. Both Sony and Mastercard were notified of the bugs at the time.

It wasn’t until a series of tests and validation of the flaw by Detectify that Adobe was notified of the bug on March 25. On May 6, Adobe issued a patch for its AEM platform.
 
According to researchers, if the vulnerability is left unpatched, attackers can easily access the CRX Package Manager to upload a malicious package within the context of Adobe’s AEM solution and execute a remote-code execution attack to “gain full control of the application,” researchers observed.

Read more: Details of RCE Bug in Adobe Experience Manager Revealed | Threatpost
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
F-Secure 26.2
Version 26.2​ R...harlan4096 — 08:11
Google Chrome’s New Split View Lets User...
Google has official...harlan4096 — 08:08
Intel shares Granite Rapids-WS Xeon 600 ...
Intel posts Xeon 6...harlan4096 — 09:49
Manjaro Linux 26.0.3 Build 260228
Manjaro Linux 26.0...harlan4096 — 08:20
K-Lite Codec Pack 19.5.0 / 19.5.4 Update
Changes in 19.5.4 ...harlan4096 — 08:19

[-]
Birthdays
Today's Birthdays
avatar (51)Claudestync
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (43)slavrProck
avatar (45)Tyesharaike
avatar (49)TomeRerla
avatar (45)walllMIZ
avatar (41)oconyho
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (45)tukraNax
avatar (41)RichardCisee
avatar (40)ebenofit
avatar (38)ykazawu
avatar (41)ARYsahulatbazar

[-]
Online Staff
There are no staff members currently online.

>