QID 150409
Date Published: 2022-02-01
QID 150409: Adobe Experience Manager: GQL Servlet Exposed
GQL Servlet is accessible. References: https://github.com/0ang3el/aem-hacker https://www.slideshare.net/0ang3el/presentations
Sensitive information might be exposed via AEM's GQLServlet. See - https://helpx.adobe.com/experience-manager/6-3/sites/developing/using/reference-materials/javadoc/index.html?org/apache/jackrabbit/commons/query/GQL.html
Solution
Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
Vendor References
CVEs related to QID 150409
Software Advisories
| Advisory ID | Software | Component | Link |
|---|