QID 150424
Date Published: 2022-02-15
QID 150424: Adobe Experience Manager: Groovy Console Exposed
The groovy console is exposed.
This allows running the groovy scripts in the AEM environment. Using the scripts the contents of JCR can be manipulated remotely.
References:
https://github.com/0ang3el/aem-hacker
https://www.slideshare.net/0ang3el/presentations
RCE is possible in Groovy Console. See - https://github.com/OlsonDigital/aem-groovy-console.
Solution
Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
Vendor References
CVEs related to QID 150424
Software Advisories
| Advisory ID | Software | Component | Link |
|---|