QID 150428
Date Published: 2022-04-22
QID 150428: Adobe Experience Manager: SSRF via Site Catalyst Servlet
SSRF via SiteCatalystServlet was detected. It might result in RCE - https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=87
A SSRF vulnerability in an application can allow an attacker to communicate or interact with an otherwise unreachable or unauthorized service. A successful attack may cause the application to disclose sensitive information to the attacker or to induce the application to retrieve and process malicious content.
Solution
Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
Vendor References
CVEs related to QID 150428
Software Advisories
| Advisory ID | Software | Component | Link |
|---|