Fiche vulnérabilité
CVE-2021-40722 : faille critique adobe experience manager (CVSS 9.8)
Description
AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that could be abused by an attacker to achieve RCE.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 13 janv. 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- adobe experience manager
- adobe experience manager cloud service