QID 150429
Date Published: 2022-04-22
QID 150429: Adobe Experience Manager: SSRF via Auto Provisioning Servlet
SSRF via AutoProvisioningServlet was detected. It might result in RCE - https://speakerdeck.com/0ang3el/hunting-for-security-bugs-in-aem-webapps?slide=87
A SSRF vulnerability in an application can allow an attacker to communicate or interact with an otherwise unreachable or unauthorized service. A successful attack may cause the application to disclose sensitive information to the attacker or to induce the application to retrieve and process malicious content.
Solution
Follow security guidelines provided by Adobe Experience Manager https://experienceleague.adobe.com/docs/experience-manager-64/administering/security/security.html?lang=en. Make sure security configuration is applied correctly.
Vendor References
CVEs related to QID 150429
Software Advisories
| Advisory ID | Software | Component | Link |
|---|