QID 150427

Date Published: 2022-04-22

QID 150427: Adobe Experience Manager: SSRF via Reporting Services Servlet

SSRF via SalesforceSecretServlet (CVE-2018-12809) was detected. See - https://helpx.adobe.com/security/products/experience-manager/apsb18-23.html

A SSRF vulnerability in an application can allow an attacker to communicate or interact with an otherwise unreachable or unauthorized service. A successful attack may cause the application to disclose sensitive information to the attacker or to induce the application to retrieve and process malicious content.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
    Vendor References

    CVEs related to QID 150427

    Software Advisories
    Advisory ID Software Component Link