Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-30683


Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a Violation of Secure Design Principles vulnerability that could lead to bypass the security feature of the encryption mechanism in the backend . An attacker could leverage this vulnerability to decrypt secrets, however, this is a high-complexity attack as the threat actor needs to already possess those secrets. Exploitation of this issue requires low-privilege access to AEM.


Published

2022-09-16T18:15:12.943

Last Modified

2025-09-19T17:19:39.570

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-657
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe experience_manager ≤ 6.5.13.0 Yes
Application adobe experience_manager - Yes

References